Impact
The vulnerability is a privilege escalation flaw that stems from a use‑after‑free in the Graphics: Canvas2D component. An attacker can trigger the flaw to corrupt or read freed memory, potentially enabling execution of arbitrary code at the privilege level of the browser or email client process. The weakness is identified as CWE-416 and may also allow out‑of‑bounds writes (CWE-787).
Affected Systems
Mozilla Firefox users running versions prior to 154, or Firefox ESR versions earlier than 140.14 or 153.1 are vulnerable. Mozilla Thunderbird users running versions prior to 154, or Thunderbird ESR versions earlier than 140.14 or 153.1 are also vulnerable. The problem is present across all supported operating systems for those releases.
Risk and Exploitability
Exploit data has not been publicly documented, but the EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The CVSS score is 8.8. Based on the description, the most likely vector involves a malicious or compromised website that renders misleading or tainted content in a Canvas2D element, enabling the use‑after‑free (CWE‑416) or out‑of‑bounds write (CWE‑787) to be triggered locally or remotely when the user visits such a page.
OpenCVE Enrichment
Debian DLA
Debian DSA