Impact
An invalid pointer in the JavaScript Engine component can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or crash the application. The flaw is classified as CWE-824. Based on the description, the flaw appears to be exploitable by delivering malicious JavaScript or by prompting the engine to dereference a null or dangling pointer.
Affected Systems
The vulnerability affects Mozilla Firefox current releases prior to version 148 and Firefox Extended Support Release (ESR) prior to 140.8, as well as Thunderbird current releases prior to version 148 and Thunderbird ESR prior to 140.8. Any installation of these products on which the JavaScript engine is active is susceptible.
Risk and Exploitability
The CVSS score of 8.8 places this vulnerability in the high severity range, while the EPSS score of less than 1% indicates a very low current exploitation probability. It is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is local or remote delivery of malicious JavaScript content through web browsing or email, exploiting the pointer dereference in the engine.
OpenCVE Enrichment
Debian DLA
Debian DSA