Impact
The CanvasWebGL component in Mozilla products contains incorrect boundary checks that can trigger both buffer overflows (CWE-119) and buffer overreads (CWE-787). An attacker can craft malicious WebGL content that causes the component to read or write outside allocated memory, leading to code execution within the browser sandbox and subsequently allowing privilege escalation to higher‑privileged levels within the system.
Affected Systems
Mozilla Firefox releases prior to version 154, including the ESR branches before 115.39, 140.14, and 153.1, are affected. Mozilla Thunderbird versions before 154 and its ESR releases before 115.39, 140.14, and 153.1 are also vulnerable.
Risk and Exploitability
The issue carries a CVSS score of 8.8. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits at this time. The likely attack vector involves delivering malicious WebGL payloads through compromised or malicious web pages, which, if executed, could exploit the buffer errors to escape the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA