Impact
Use‑after‑free flaw in the JavaScript: WebAssembly component allows an attacker to corrupt memory or execute arbitrary code after the object is prematurely freed. This can lead to remote code execution and full system compromise in privileged browser contexts. The issue is mapped to CWE‑416 and CWE‑825.
Affected Systems
Firefox releases prior to 154, and the ESR 140.14 and 153.1 versions, as well as Thunderbird versions older than 154, including the ESR 140.14 and 153.1 releases, remain vulnerable. All newer builds contain the fix.
Risk and Exploitability
The CVSS score of 9.8 marks the flaw as critical, yet the EPSS score of < 1 % suggests a very low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog and no public exploits are known. Based on the description, the likely attack vector involves malicious JavaScript or WebAssembly content served from an attacker‑controlled web site, a scenario that has been inferred from the component’s function.
OpenCVE Enrichment
Debian DLA
Debian DSA