Impact
A use‑after‑free flaw was discovered in the JavaScript garbage collector. The advisory does not detail the exact consequences, but typical use‑after‑free bugs in a browser’s JavaScript engine enable memory corruption that can lead to arbitrary code execution. The problem was addressed in Firefox 154 and the corresponding ESR branch 153.1, and also in Thunderbird 154 and 153.1.
Affected Systems
Affected releases are all versions of Mozilla Firefox and Firefox ESR prior to 154 and 153.1, respectively, and all Thunderbird releases prior to 154 and 153.1. The advisory does not list any other affected version ranges.
Risk and Exploitability
The CVSS score is 8.8 and the EPSS score is 0.00292 (approximately 0.3%). The vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to deliver malicious JavaScript – for example via a compromised or malicious website – to trigger the use‑after‑free. Considering typical browser exploitation trends, the risk of exploitation is significant, especially if a user visits an untrusted site or executes injected code.
OpenCVE Enrichment