Impact
Incorrect boundary checks in the CanvasWebGL component allow an attacker to write beyond intended memory bounds, which can corrupt process state or lead to arbitrary code execution. The flaw is identified as CWE‑120 and CWE‑787. When triggered, the vulnerability enables an attacker to gain higher privileges than those originally granted to the compromised process, potentially allowing modification or execution of arbitrary code within the browser or email client context.
Affected Systems
Mozilla Firefox versions prior to 156, excluding Firefox ESR 115.41, ESR 140.16, and ESR 153.3, as well as Mozilla Thunderbird versions prior to 156, excluding Thunderbird ESR 140.16 and ESR 153.3, are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is less than 1%, indicating a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw, based on its boundary‑handling weaknesses (CWE‑120 and CWE‑787), by delivering malicious web content that invokes the vulnerable WebGL API, leading to privilege escalation within the user's browser or email client. The vulnerability is local to the user’s operating system privileges but can be triggered by any web page or mail content the user opens, highlighting the need for immediate remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA