Impact
The vulnerability is a use‑after‑free in the graphics text rendering subsystem of Mozilla. It can corrupt memory during text rendering. The CVE description does not claim a confirmed execution path, so the exact impact is uncertain; memory corruption could lead to crashes or, in severe cases, arbitrary code execution.
Affected Systems
Mozilla Firefox browsers and Thunderbird email clients, including both stable and ESR branches, are affected. All versions prior to Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1, Thunderbird 154, Thunderbird 140.14, or Thunderbird 153.1 are vulnerable, as the fix was applied only in those releases and newer ones.
Risk and Exploitability
Mozilla Firefox browsers and Thunderbird email clients, including both stable and ESR branches, are affected. All versions prior to Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1, Thunderbird 154, Thunderbird 140.14, or Thunderbird 153.1 are vulnerable. The EPSS score of < 1% and the fact that the CVE is not listed in the CISA KEV catalog mean the exact probability of exploitation is unclear, but the CVSS score of 9.8 indicates a critical severity if exploited. A use‑after‑free flaw in a graphics component can usually be triggered by rendering malicious content from a webpage, which is inferred from the component’s role; however, exploitation would require the browser to process the offending content. The potential impact is high if the flaw is successfully leveraged.
OpenCVE Enrichment
Debian DLA
Debian DSA