Impact
A flaw in Mozilla's Graphics: Text component permits reading of internal memory that may contain sensitive information such as passwords, session cookies, or other confidential data. The vulnerability exploits improper handling of text rendering data, leading to unintended data exposure without the need for elevated privileges. The weakness is classified as an information exposure vulnerability.
Affected Systems
Mozilla Firefox versions prior to 154, as well as the Firefox ESR releases 115.39, 140.14, and 153.1, are impacted. Similarly, Mozilla Thunderbird versions before 154, and the Thunderbird ESR releases 140.14 and 153.1, experience the same flaw. All newer builds contain the correction.
Risk and Exploitability
Based on the description, the likely attack surface involves local or web-originated content that triggers the Graphics: Text component to read memory, enabling an attacker to capture sensitive information. The CVSS score is 6.5, and the EPSS score indicates an exploitation probability of less than 1%; the issue is not listed in CISA's KEV catalog, which together indicate limited exploitation data. While no widespread exploits have been reported, the potential for significant data loss recommends immediate mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA