Impact
This vulnerability is caused by incorrect boundary checks in the Layout: Grid component of Mozilla Firefox and Mozilla Thunderbird. If the component encounters input that violates the expected boundaries, it can result in a crash of the browser or mail client process. The CVE description does not indicate any escalation to code execution or privilege escalation; the primary risk is a sudden loss of functionality for the affected user.
Affected Systems
All installations of Mozilla Firefox that are running a version older than 155 and use the Layout: Grid feature are susceptible. The vulnerability was addressed in Firefox 155, so any pre‑155 build should be considered vulnerable. All installations of Mozilla Thunderbird that are running a version older than 155 and use the Layout: Grid feature are also susceptible. The vulnerability was addressed in Thunderbird 155, so any pre‑155 build should be considered vulnerable.
Risk and Exploitability
The CVSS score is 4.3, EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of exploitation is still unclear. Based on the component's role in rendering web content, it is reasonable to infer that a remote attacker could trigger the flaw by presenting a specially crafted web page that forces the grid layout to process malformed parameters, leading to a browser crash. No information suggests that multiple attempts or persistence are required, but the absence of a severity rating means the exact exploitation probability cannot be determined.
OpenCVE Enrichment