Impact
The vulnerability consists of multiple internally found bugs in Firefox 154 and Firefox ESR 153.1 that caused memory corruption or other security-relevant defects. The memory errors could be exploited with sufficient effort, potentially allowing an attacker to execute arbitrary code within the browser’s context, leading to a compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
Firefox 154 and Firefox ESR 153.1 are affected. The bugs are fixed in Firefox 155 and Firefox ESR 153.2, so systems running those earlier releases are susceptible.
Risk and Exploitability
No CVSS score is publicly available, and the EPSS score is not reported, indicating no current data on exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on typical exploitation pathways for memory corruption in web browsers, the likely attack vector is through a malicious web page or extension loaded in the affected Firefox versions. An attacker would need to craft content that triggers the underlying memory error; no public exploitation has been documented yet, but the potential for abuse remains.
OpenCVE Enrichment