Impact
The flaw arises from an invalid pointer dereference in the Audio/Video Web Codecs component. When the system processes media data that causes this dereference, the component crashes, leading to a temporary halt of media playback or browser instability. The vulnerability corresponds to CWE-476, CWE-416, and CWE-400. The primary impact is loss of availability, which can be disruptive for end users and critical services relying on uninterrupted media functionality.
Affected Systems
Mozilla Firefox versions prior to 151 and the ESR release prior to 140.11 are affected. The vulnerability is tied to the Web Codecs API within Firefox’s audio and video subsystem.
Risk and Exploitability
The CVSS score for this vulnerability is 7.5; EPSS is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is the delivery of crafted media data via a malicious web page or application that leverages the Web Codecs API. An attacker would need to force the browser to process such data to trigger the crash; no publicly available exploitation tools are known for this defect.
OpenCVE Enrichment