Impact
The vulnerability resides in the Graphics: CanvasWebGL component where improper boundary checks allow a malicious entity to read memory beyond intended limits. This buffer over-read can lead to privilege escalation, enabling attacker code to execute with higher privileges than the user context, potentially compromising the entire system. The weakness is classified as CWE‑120, indicating a failure to validate buffer boundaries.
Affected Systems
Products affected include Mozilla Firefox and Mozilla Thunderbird across all versions released prior to Firefox 156, Firefox ESR 115.41, 140.16, 153.3, and Thunderbird 156, ESR 140.16. Any deployments using these earlier versions, regardless of the platform, are vulnerable until the cited updates are applied.
Risk and Exploitability
The listed CVSS score of 8.8 marks this vulnerability as high severity, and the EPSS score of < 1% indicates a low probability of exploitation. The absence from the CISA KEV catalog does not negate the risk; attackers could exploit the flaw through specially crafted web pages or extensions that exercise the CanvasWebGL API. The attack vector is likely remote from a web context, and the flaw requires input that oversteps established bounds within the graphics processing routine.
OpenCVE Enrichment
Debian DLA
Debian DSA