Impact
A use‑after‑free flaw exists in the audio/video playback component. While processing media, the component may free a memory block that is still referenced. This results in program state corruption, which can cause a crash or create an opportunity for arbitrary code execution, depending on surrounding code. The advisory does not explicitly detail the exploitation path, so the exact impact is limited to what typical use‑after‑free bugs allow.
Affected Systems
Mozilla Firefox versions older than 148, Firefox ESR builds prior to 115.33 and 140.8, and Mozilla Thunderbird releases older than 148, as well as Thunderbird ESR builds before 140.8, are affected. These versions have been patched in the listed releases, and no additional Mozilla products are reported vulnerable.
Risk and Exploitability
The CVSS score of 8.8 categorizes the vulnerability as High severity. The EPSS score of less than 1% indicates a very low likelihood of currently active exploitation. The likely attack vector, inferred from the description that the flaw resides in the playback component, is an attacker delivering a malicious media file or stream to the browser or email client. If successfully exploited, the attacker could potentially obtain remote code execution on the target system with the privileges of the application, but this conclusion is based on typical use‑after‑free behavior rather than direct evidence in this advisory.
OpenCVE Enrichment
Debian DLA
Debian DSA