Impact
This vulnerability is caused by incorrect boundary conditions in the Audio/Video: Web Codecs component, which can lead to memory corruption and application crashes. The bug is related to lack of proper bounds checking (CWE‑131) and may allow an attacker to supply malformed media data that triggers an out‑of‑bounds write (CWE‑754). When processed by an affected application, the result is typically a denial of service rather than arbitrary code execution.
Affected Systems
The flaw impacts Mozilla's Firefox browser and Thunderbird email client. All versions prior to Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9 are affected. The security advisories confirm that the issue was fixed in those releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. The EPSS score of less than 1 % suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA's KEV catalog. The most plausible attack scenario involves an attacker creating or sending a malicious media stream or file that is processed by Web Codecs. If the target system loads or previews such content, the bounds error can be triggered, causing a crash and a denial of service to the user.
OpenCVE Enrichment
Debian DLA
Debian DSA