Impact
A race condition in the Graphics WebRender component can lead to a use‑after‑free, corrupting memory. An attacker that can trigger the fault may cause arbitrary memory reads or writes, potentially leading to code execution, data leakage, or crashes. The flaw is a concurrency control weakness (CWE‑362, 364) coupled with a resource management error (CWE‑416).
Affected Systems
Mozilla Firefox and Thunderbird are affected in all releases before Firefox 149, Firefox ESR 115.34 and 140.9, and Thunderbird 149 and 140.9. Versions equal to or newer than these contain the fix.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1 % suggests a low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attack vector is not explicitly documented; based on the component, the likely vector is a locally exploitable condition such as a malicious web page or local process, but remote exploitation is not confirmed.
OpenCVE Enrichment
Debian DLA
Debian DSA