Impact
The vulnerability is a use‑after‑free flaw in the WebGPU component of Mozilla’s Graphics engine. When exploited, it allows code execution with the same privileges as the currently running Firefox or Thunderbird process, thereby enabling an attacker to gain elevated authority on the affected system. The weakness conforms to the definition of Use‑After‑Free, identified as CWE‑416.
Affected Systems
All versions of Mozilla Firefox released before the security fixes in Firefox 155 and Firefox ESR 153.2 are impacted, as are all older releases of Mozilla Thunderbird prior to Thunderbird 155 and Thunderbird 153.2. The flaw is confined to these products regardless of operating system or hardware platform. No other vendors or products are listed as affected.
Risk and Exploitability
Given the high severity CVSS score of 8.8, the flaw permits privilege escalation with significant potential impact to confidentiality, integrity, and availability. The attack vector is inferred to be through malicious web content that engages WebGPU resources, requiring the user to visit or load such content. No EPSS score is available, so exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploitation at the time of reporting.
OpenCVE Enrichment