Impact
The vulnerability originates in Firefox’s DOM Navigation component, where a use‑after‑free condition allows an attacker to escape the browser sandbox. This flaw can enable arbitrary code execution or compromise of the host system, affecting confidentiality, integrity, and availability.
Affected Systems
Mozilla Firefox, including the standard release channel and the ESR channels. Affected releases are those prior to Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15 and Firefox ESR 153.2. Users on any of those versions are impacted.
Risk and Exploitability
The likelihood of exploitation is unknown because no EPSS score exists, and there are no publicly documented exploits at this time. However, the ability to escape the browser sandbox indicates a high potential to compromise the operating system, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through malicious web content that activates the navigation component, though such an attack has not yet been demonstrated in the wild.
OpenCVE Enrichment