Impact
The flaw arises from an invalid pointer dereference in the Audio/Video Web Codecs component. When media data that triggers this dereference is processed, the component crashes, resulting in a temporary loss of media playback or browser instability. This defect is a denial‑of‑service weakness and is identified with CWE‑400. The primary impact is loss of availability, disrupting end‑user experience and any applications depending on uninterrupted media functionality.
Affected Systems
Mozilla Firefox versions prior to 151 and the ESR release prior to 140.11 are affected. The vulnerability is tied to the Web Codecs API within Firefox’s audio and video subsystem.
Risk and Exploitability
The CVSS score for this vulnerability is 7.5; EPSS is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is the delivery of crafted media data via a malicious web page or application that leverages the Web Codecs API. An attacker would need to force the browser to process such data to trigger the crash; no publicly available exploitation tools are known for this defect.
OpenCVE Enrichment
Debian DLA
Debian DSA