Impact
A use‑after‑free condition exists within the audio/video processing module of Mozilla Firefox. If triggered, an attacker could potentially execute arbitrary code, hijack execution flow, or cause a denial of service by exploiting corrupted memory. The vulnerability is a classic example of a memory management flaw that undermines process integrity and could lead to privilege escalation if not mitigated. The likely attack vector includes malicious media content or a crafted audio stream delivered through a website, library, or file that the browser processes.
Affected Systems
Vulnerable instances are found in Mozilla Firefox versions prior to 155, as well as legacy ESR releases before 140.15 and 153.2. Users running any of these builds are at risk until they apply the referenced fixes. Modern releases beyond the mentioned thresholds are not affected.
Risk and Exploitability
Because the vulnerability involves a fundamental memory corruption bug, the severity is high. No CVSS score or EPSS figure is available in the current advisory, and the vulnerability is not yet listed in the CISA KEV catalog; however, the absence of these metrics does not reduce the potential impact. Attackers can likely trigger the flaw via crafted audio/video data, making it readily exploitable in a browser context. Given the historical pattern of use‑after‑free bugs, a real‑world exploitation is plausible if the vulnerability remains unpatched.
OpenCVE Enrichment