Impact
A malformed PDF file can trigger a crash in the PDF Viewer component, causing the browser to terminate unexpectedly and blocking further user interaction. The denial of service is local to the user's machine, preventing access to web content during a session and potentially disrupting automated scripts or kiosk operations.
Affected Systems
All Mozilla Firefox installations prior to version 155 are susceptible. Users of Windows, macOS, or Linux running an outdated build are at risk if they view or download PDFs that exploit this flaw.
Risk and Exploitability
The likelihood of exploitation cannot be quantified due to the absence of an EPSS score, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it can be inferred that an attacker can supply a specially crafted PDF file to a victim, triggering the crash when the file is opened in the PDF Viewer. Without a patch, the vulnerability remains exploitable as long as users run affected versions.
OpenCVE Enrichment