Impact
This vulnerability involves undefined behavior in the WebRTC signaling component of Mozilla products. Undefined behavior can lead to memory corruption or arbitrary code execution within the application’s process. The 9.8 CVSS score reflects the potential for complete compromise of the affected process and significant impact on confidentiality, integrity, and availability.
Affected Systems
Mozilla Firefox up through version 148, Firefox ESR up to version 140.8, Mozilla Thunderbird up through version 148, and Thunderbird ESR up to version 140.8 are vulnerable. Versions 149 for Firefox and 140.9 for ESR versions include the fix and are no longer vulnerable.
Risk and Exploitability
The CVSS score of 9.8 places this issue in the critical range, indicating severe potential damage if exploited. The EPSS score below 1% suggests that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to involve a maliciously crafted WebRTC signaling message, which could be sent via a web page or an email link. However, the official description does not explicitly detail the exploitation conditions, so this inference remains speculative."
OpenCVE Enrichment
Debian DLA
Debian DSA