Impact
A flaw in the graphics subsystem of Mozilla Firefox and Thunderbird allows the graphics component to read and expose data that should remain private. The weakness corresponds to information exposure and a memory access issue, potentially leading to accidental or intentional disclosure of data processed by the graphics layer.
Affected Systems
Mozilla Firefox versions earlier than 154, as well as the ESR releases 115.39, 140.14, and 153.1, are vulnerable. Likewise, Mozilla Thunderbird versions before 154, and the ESR releases 140.14 and 153.1, can be affected. Any installation of these older releases remains susceptible until a newer version is installed.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% signals a low probability of exploitation as of the latest data. The vulnerability is not listed in CISA's KEV catalog, meaning no publicly documented exploits are known. The advisory does not specify a particular attack vector, and additional details on how an attacker might trigger the disclosure are not provided in the captured description.
OpenCVE Enrichment
Debian DLA
Debian DSA