Impact
The vulnerability arises from uninitialized memory usage within the Graphics: Text component of Firefox and Thunderbird. This flaw can expose whatever garbage data happens to occupy the memory region, potentially leaking sensitive information or affecting the integrity of rendered content. The listed CWEs indicate that uninitialized variables and improper handling of input may allow exploitation. Depending on the environment, an attacker could manipulate rendered text to reveal internal data or cause unintended behavior.
Affected Systems
Mozilla Firefox and Thunderbird are affected by this flaw. All versions prior to Firefox 148 and Thunderbird 148 are vulnerable, as the issue was fixed in these releases. The advisory MFSA 2026‑13 and MFSA 2026‑16 reference the related bug (2006199).
Risk and Exploitability
The CVSS base score of 9.1 signifies a severe risk. The EPSS score of <1% indicates low but nonzero exploitation probability. The vulnerability is not listed in the KEV catalog. The likely attack vector is local or remote through the rendering of malicious content, as the flaw occurs within the Graphics: Text component. Exploitation would generally require the victim to load crafted text that triggers the use of the uninitialized memory.
OpenCVE Enrichment