Impact
The CanvasWebGL component contains incorrect boundary checks that allow an attacker to read or write memory beyond the intended buffer limits. This unsafe buffer copy (CWE‑120) can be leveraged to elevate privileges within the context of the user’s process, potentially granting higher‑level access to the host system. No other effects such as information disclosure or arbitrary code execution are documented in the CVE description.
Affected Systems
Mozilla Firefox versions prior to 156, Firefox ESR releases prior to 115.41, prior to 140.16, and prior to 153.3, as well as Thunderbird versions prior to 156, prior to 140.16, and prior to 153.3, are affected. Updated releases contain the fix.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The vulnerability is not listed in CISA KEV, and the EPSS score is <1%, indicating a very low but nonzero exploitation probability. The likely attack vector is a crafted WebGL page or an email attachment that triggers the component to render malicious content. Exploitation requires user interaction to load the content, after which the flaw can be triggered from within the user's process, achieving privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA