Impact
The issue is an incorrect handling of boundary conditions within the Audio/Video: Web Codecs component used by Mozilla applications, which may lead to memory corruption. The vulnerability is categorized under CWE‑131 (Incorrect Buffer Size Calculation) and CWE‑754 (Improper Handling of the Procedure Chain).
Affected Systems
Mozilla Firefox (all builds) versions earlier than 149 and Firefox ESR versions earlier than 140.9, as well as Mozilla Thunderbird versions earlier than 149 and Thunderbird ESR versions earlier than 140.9, are affected.
Risk and Exploitability
The CVSS score of 7.5 places this issue in the high‑risk category, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not included in the CISA KEV catalog. The likely attack vector, inferred from the nature of the component, involves an attacker supplying a malformed audio or video file that the browser or Thunderbird processes, which could trigger the boundary failure.
OpenCVE Enrichment
Debian DLA
Debian DSA