Impact
The flaw arises from incorrect handling of boundary conditions in the audio and video subsystem, resulting in a buffer under-read (CWE-125). An attacker could supply a crafted media file that causes the component to read beyond the intended data region, potentially revealing sensitive data stored in memory. The description explicitly states the vulnerability stems from improper buffer boundary checks, which directly supports the confidentiality impact.
Affected Systems
Mozilla products, specifically Firefox and Thunderbird, are affected. All releases before Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9 contain the flaw as documented in the security advisories. Users of these older versions are at risk until they upgrade.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests that active exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker would need to deliver a malicious media file that a user opens or plays in the affected application. This implies a local or remote user‑interaction attack vector, and the flaw is not exploitable without the user's activity, which is an inferred assumption from the available data.
OpenCVE Enrichment
Debian DLA
Debian DSA