Impact
The updated description confirms a use‑after‑free flaw in the Audio/Video component of Mozilla Firefox and Thunderbird. The flaw allows an attacker to access freed memory, potentially enabling arbitrary code execution. If exploited, the attacker could gain full control of the affected system, compromising confidentiality, integrity, and availability. The weakness is identified as a memory corruption issue, which falls into the common weakness category of use‑after‑free.
Affected Systems
The affected products are Mozilla Firefox and Mozilla Thunderbird. In Firefox, versions prior to 155, or earlier than ESR 115.40, 140.15, or 153.2, are vulnerable. In Thunderbird, versions prior to 155, or earlier than ESR 140.15 or 153.2, are also vulnerable. Users running these earlier releases should upgrade to the patched versions to mitigate the issue.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 5.4, reflecting medium severity. The likely attack vector is the delivery of malicious audio or video content, which an attacker can trigger through a web page or local media file. Without a patch, exploitation remains possible and could lead to arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA