Impact
The flaw is a miscompilation bug in Firefox and Thunderbird’s JavaScript engine JIT component. Crafted JavaScript can be compiled into incorrect machine instructions, allowing an attacker to execute arbitrary code with the permissions of the browser process. The vulnerability is a direct JIT component deficiency that can be leveraged for remote code execution. Based on the description, the likely attack vector is malicious JavaScript delivered via web pages.
Affected Systems
Firefox versions older than 154 and the ESR 140.14 and ESR 153.1 releases are impacted, as are Thunderbird versions older than 154 and the ESR 140.14 and ESR 153.1 releases. No other vendors or products are listed in the CVE record.
Risk and Exploitability
The EPSS score is <1%, indicating a very low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so there are no known public exploits. The CVSS score of 6.5 indicates moderate severity; the potential for arbitrary code execution indicates high-impact risk. Exploitation would almost certainly require an attacker to supply malicious JavaScript or host a harmful web page, a scenario that is feasible over the internet, but the exact likelihood remains uncertain given the lack of public exploitation data.
OpenCVE Enrichment
Debian DLA
Debian DSA