Impact
The vulnerability is an integer overflow within the graphics rendering subsystem. The flaw occurs when processing image data, allowing an attacker to send crafted image content that overflows a numeric counter, potentially corrupting memory and enabling remote code execution or denial of service. This type of bug is classified as CWE‑190, Integer Overflow or Wrap.
Affected Systems
All installations of Mozilla Firefox older than version 154 and the ESR branch before 153.1, and all installations of Mozilla Thunderbird older than version 154 and the ESR branch before 153.1, are affected. The fix was applied in Firefox 154, ESR 153.1, Thunderbird 154, and Thunderbird 153.1; any user running those older builds is at risk.
Risk and Exploitability
The flaw is triggered during rendering of malicious web content or image data in the graphics engine of both Firefox and Thunderbird. The likely attack vector is a crafted web page or image served over the internet. Although the EPSS score is unavailable and the vulnerability is not listed in CISA KEV, the CVSS score of 7.5 indicates a high severity. Memory corruption from this integer overflow could lead to remote code execution or denial of service if successfully exploited.
OpenCVE Enrichment