Impact
An invalid pointer in the Graphics component of Firefox and Thunderbird can be exploited to gain elevated privileges on the host system. The flaw occurs when graphics data is processed and results in memory corruption, allowing an attacker to execute code within the browser process. Because the browser runs with the user's credentials, this can lead to full system compromise by escaping the sandbox. This vulnerability represents a pointer dereference issue, classified as CWE-763 and CWE-825. The issue is fixed by upgrading to Firefox 154 or later, ESR 153.1 or later, Thunderbird 154 or later, or Thunderbird 153.1 or later.
Affected Systems
Versions of Firefox before 154 on the standard release channel and before 153.1 on the Extended Support Release (ESR) channel are impacted. The flaw exists across all platforms where the Graphics component is active, including Windows, macOS, and Linux distributions.
Risk and Exploitability
The CVSS score of 8.8 is provided in the available data, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves local exploitation through graphics content rendering, such as images or web pages. While exploitation may require user interaction to trigger graphics processing, the potential for privileged code execution makes it a high‑severity risk for affected users.
OpenCVE Enrichment