Impact
The Graphics: ImageLib component contains a use‑after‑free flaw that can be triggered by crafted image data. The flaw may allow an attacker to execute code in the context of the browser or email client because freed memory can be overwritten, leading to arbitrary code execution. This weakness involves a use‑after‑free and inappropriate memory deallocation (CWE‑416 and CWE‑825).
Affected Systems
All Mozilla Firefox releases prior to version 154, and all ESR releases before 115.39, 140.14, and 153.1, as well as all Mozilla Thunderbird releases before 154, 140.14, and 153.1, are vulnerable. The vulnerability is specific to the Graphics: ImageLib component in both browsers.
Risk and Exploitability
The CVSS score is 9.8, indicating critical severity. The EPSS score is < 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. It is inferred that the flaw can be triggered by malicious image data typically delivered via a website or an infected file, and that an attacker only needs the victim to load or view the image; no additional user interaction is required. Because an arbitrary code execution outcome is possible, the risk remains high, and the exploitation probability, while low, suggests that immediate action is warranted.
OpenCVE Enrichment
Debian DLA
Debian DSA