Impact
The vulnerability is a use‑after‑free bug in the DOM: Core & HTML component of Mozilla Firefox. It occurs when the browser frees an object in the Document Object Model and later accesses it again, leading to memory corruption. This flaw can potentially crash the browser or allow an attacker to execute arbitrary code in the context of the page. The weakness corresponds to CWE‑416.
Affected Systems
The affected product is Mozilla Firefox. Versions before 155, and older ESR releases before 140.15 and 153.2, contain the flaw. Users running these releases are vulnerable.
Risk and Exploitability
While the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the nature of the use‑after‑free error implies a high potential for remote exploitation. The likely attack vector is a malicious web page that causes the browser to free an object and then reuse it. Because no public workaround exists, the safest mitigation is to upgrade to a fixed release.
OpenCVE Enrichment