Impact
A use‑after‑free flaw exists in the JavaScript garbage collector of Mozilla Firefox. The vulnerability can allow an attacker to trigger the interpreter to read or execute memory that is no longer valid, potentially leading to arbitrary code execution or a denial‑of‑service condition. The CVE record states the issue was fixed in Firefox 155 and Firefox ESR 153.2, but does not provide a detailed exploitation chain; it is inferred that exploitation would require a specially crafted JavaScript payload delivered to a vulnerable user or local client.
Affected Systems
Mozilla Firefox use‑after‑free vulnerabilities affect all releases prior to version 155 for the standard build and prior to ESR 153.2 for the extended‑support channel. Any system running a vulnerable build of Firefox is impacted until a patched version is deployed.
Risk and Exploitability
The EPSS score for this flaw is not available and it is not listed in the CISA Known Exploited Vulnerabilities catalog, so the public exploitation probability is unclear. However, use‑after‑free conditions in the JavaScript engine are generally considered high‑severity CVSS‑based and can be exploited remotely via web pages, making the risk significant. The lack of a known KEV listing suggests no publicly observed exploitation yet, but the inherent nature of the flaw warrants immediate attention.
OpenCVE Enrichment