Impact
The vulnerability originates from incorrect boundary checks in the Graphics: CanvasWebGL component, classified as a buffer overflow (CWE‑120). This flaw can allow attackers to overwrite memory controlling the component, potentially escalating privileges when a user processes malicious content that triggers the flaw. According to the official description, the compromised boundary checks are sufficient to compromise memory safety and elevate privileges within the affected process.
Affected Systems
The flaw affects Mozilla Firefox and Mozilla Thunderbird. All releases before Firefox 156 contain the vulnerable component, while Firefox 156 and later, and all ESR releases from 115.41 onward, are not affected. Versions of Thunderbird prior to 156 are vulnerable, and Thunderbird 156 or newer—including ESR 140.16 and later—contain the fix.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation, and the absence of a KEV listing means no known public exploits have been reported. Based on the description and the known WebGL entry point, the likely attack vector involves malicious WebGL content delivered through a web page or an email attachment that the user views. The attacker would need to supply crafted WebGL code that causes the improper bounds check to trigger, which could lead to privilege escalation on the victim's machine.
OpenCVE Enrichment
Debian DLA
Debian DSA