Impact
The flaw arises from incorrect boundary checks in the Graphics: CanvasWebGL component. An attacker can supply crafted graphics data that causes the component to access memory outside of intended bounds, which may lead to a privilege‑escalation condition. The vulnerability allows the user running the affected application (Firefox or Thunderbird) to elevate privileges, enabling unauthorized manipulation of data or further exploitation within the user session.
Affected Systems
Mozilla Firefox versions earlier than 156 and all pre‑156 releases, as well as all earlier ESR releases except those explicitly patched (Firefox ESR 115.41, 140.16, and 153.3) are affected. Likewise, all Thunderbird releases before 156, and earlier ESR releases prior to ESR 140.16 and ESR 153.3, are impacted. The listed patched ESR releases and newer releases contain the fix that corrects the boundary checks.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The most likely exploitation scenario involves delivering crafted content that exploits the CanvasWebGL component, but the exact attack vector is inferred from the nature of the graphics processing flaw and is not explicitly detailed in the advisory.
OpenCVE Enrichment
Debian DLA
Debian DSA