Impact
This vulnerability involves uninitialized memory access within the Audio/Video: Web Codecs component of Mozilla products, classified as CWE-457 and CWE-824. The flaw permits the reading of memory that has not been initialized, potentially exposing sensitive data and causing application instability. The issue has been mitigated in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected Systems
The affected vendor is Mozilla, specifically the Firefox browser and Thunderbird mail client. The flaw exists in all versions prior to Firefox 150 and Firefox ESR 140.10, as well as Thunderbird versions before 150 and Thunderbird ESR 140.10, where the Web Codecs API could access memory that was never initialized.
Risk and Exploitability
The CVSS score of 7.3 indicates a high potential impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Because the flaw occurs in the Web Codecs API, it is most likely exploitable through malicious web content that leverages the codec functionality. No confirmed exploits exist, but the potential for data leakage warrants patching before any exploit is discovered. The attack vector is likely remote, delivered via web pages, but the specific feasibility remains uncertain.
OpenCVE Enrichment
Debian DLA
Debian DSA