Impact
The vulnerability arises from internally identified bugs in Firefox 154, Firefox ESR 153.1 and Firefox ESR 140.14 that caused memory corruption or other security‑relevant defects. Some of these bugs could be leveraged, with sufficient effort, to achieve arbitrary code execution or to cause denial of service. The description acknowledges a potential risk but does not confirm a known exploit. Therefore, the primary impact is the possibility of remote code execution or system compromise.
Affected Systems
Mozilla Firefox is affected when running versions prior to Firefox 155, Firefox ESR 140.15, or Firefox ESR 153.2. The bugs are present in Firefox 154, Firefox ESR 153.1, and Firefox ESR 140.14. The affected products are specifically Mozilla:Firefox with the stated versions.
Risk and Exploitability
No CVSS score is published, and the EPSS score is unavailable, making the exact risk level unclear. The vulnerability is not currently listed in the CISA KEV catalog. Memory corruption defects are generally considered serious; however, without a publicly documented exploit the likelihood of attack remains uncertain. Nonetheless, the potential for high‑severity exploitation justifies treating the issue as a high‑risk security concern.
OpenCVE Enrichment