Impact
A use‑after‑free flaw exists in the JavaScript garbage‑collection component of Mozilla products. This vulnerability can cause memory corruption and may lead to crashes or other undefined behavior as a freed memory area is still referenced, classified as CWE‑416.
Affected Systems
Mozilla Firefox and Thunderbird are affected. All releases prior to version 148 are vulnerable; the issue is fixed in Firefox 148 and Thunderbird 148.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity rating. EPSS is less than 1 %, suggesting that large‑scale exploitation is unlikely at the moment, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves malicious JavaScript content that triggers garbage collection while a freed memory location is still referenced, potentially leading to crashes or memory corruption. The combination of a high severity score and remote exploitation vector warrants rapid remediation.
OpenCVE Enrichment