Impact
The Canvas2D graphics engine contains improper boundary checks that enable out-of-bounds memory reads or writes during canvas processing, resulting in memory corruption and unstable application behavior. The flaw is aligned with CWE-754 and CWE-823 weaknesses.
Affected Systems
Mozilla Firefox and Thunderbird releases before the fixes are vulnerable. Any Firefox version earlier than 149, ESR 115.34, or ESR 140.9, and Thunderbird versions earlier than 149 or ESR 140.9 contain the issue.
Risk and Exploitability
The vulnerability carries a high severity rating, but the likelihood of exploitation remains low and it is not listed in the known exploited catalog. Attackers would need to supply a malicious web page or email that triggers the Canvas2D API, which the victim’s browser processes. Successful exploitation could corrupt memory, potentially causing crashes or, in rare cases, escalating to a more severe compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA