Impact
The CVE description states an incorrect boundary condition within the WebRTC component of Mozilla browsers and Thunderbird. This flaw could enable a buffer overrun or other form of memory corruption when processing malformed WebRTC packets, potentially allowing an attacker to crash the application or, in the worst case, execute arbitrary code.
Affected Systems
Firefox releases older than version 150—including the ESR branches before 115.35 and 140.10—are vulnerable, as are Thunderbird builds released before version 150 or before 140.10. Both products use the WebRTC stack, so any user of these outdated versions could be exposed.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, while the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would most likely target the flaw via malicious webpages or controlled WebRTC streams that deliver specially crafted packet data, so user-facing applications should be updated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA