Impact
A use‑after‑free bug exists in the Layout: Text and Fonts component of Mozilla Firefox. Based on the description, the flaw allows a freed memory object to be accessed again, which may enable a malicious webpage to read or modify that memory. This could cause browser crashes or, in vulnerable builds, arbitrary code execution under the user’s privileges, affecting confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects all Mozilla Firefox releases prior to Firefox 154, including Firefox ESR 115.39, ESR 140.14, and ESR 153.1. Users running any of these versions are at risk until they upgrade to a patched release. The same applies to Thunderbird releases prior to Thunderbird 154, ESR 140.14, and ESR 153.1.
Risk and Exploitability
Despite the EPSS score being below 1% and the vulnerability not being listed in CISA KEV, the use‑after‑free flaw carries a high‑severity exploitation vector that could be leveraged for remote code execution if an attacker can drive a victim to load a specially crafted web page. The CVSS score is 8.8. The lack of publicly reported exploits does not mitigate the inherent risk of the vulnerability, which permits arbitrary memory manipulation and control flow hijacking.
OpenCVE Enrichment
Debian DLA
Debian DSA