Impact
Incorrect boundary conditions in the Audio/Video: GMP component cause out‑of‑bounds writes or reads during media processing. The flaw can corrupt memory, leading to potential data leakage, program instability, or execution of arbitrary code if the attacker controls the media input.
Affected Systems
Mozilla Firefox (v149 and newer) and Firefox ESR 115.34 or 140.9 and newer) and Mozilla Thunderbird (v149 and newer) and Thunderbird ESR 140.9 and newer) are affected.
Risk and Exploitability
The vulnerability scores 7.5 on CVSS, indicating high severity, but EPSS is below 1%, suggesting low exploitation probability. The defect is not listed in CISA’s KEV catalog. Attackers could trigger this condition by delivering crafted media—through a web page, email attachment, or other media‑processing channel—making the primary vector likely external content. Successful exploitation could corrupt application memory and enable further compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA