Impact
A Use‑After‑Free (CWE-416) flaw involving improper memory management (CWE-825) resides in the Audio/Video: Web Codecs component of Mozilla Firefox and Thunderbird. The bug enables a freed object to be accessed again, potentially corrupting memory. While the current data do not confirm arbitrary code execution, the memory corruption could trigger application crashes or compromise the confidentiality, integrity, or availability of the browser process.
Affected Systems
Mozilla Firefox builds older than version 156 and any ESR releases older than 140.16 or 153.3 are vulnerable. The same applies to Mozilla Thunderbird: all products before version 156 and any ESR releases before 140.16 or 153.3 contain the flaw. The vulnerability is fixed in Firefox 156, ESR 140.16, 153.3 and in Thunderbird 156, ESR 140.16, 153.3.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious or compromised web page that invokes the Web Codecs API, meaning the client must run the vulnerable browser version. Successful exploitation could lead to memory corruption within the browser process, potentially affecting availability and data integrity.
OpenCVE Enrichment
Debian DLA
Debian DSA