Impact
A flaw in the CanvasWebGL component of Mozilla browsers allows an attacker to exploit incorrect boundary checks, potentially elevating privileges. The vulnerability is designated as a buffer-related weakness (CWE-120) and is cataloged with a high CVSS score of 8.8.
Affected Systems
The issue affects Mozilla's Firefox and Thunderbird products. Fixed versions include Firefox 156, Firefox ESR 115.41, 140.16, and 153.3, as well as Thunderbird 156 and Thunderbird 140.16.
Risk and Exploitability
With a CVSS of 8.8, the severity is high. The EPSS score is very low, under 1%, and the vulnerability is not listed in KEV, indicating limited public exploitation so far. The attack vector is likely remote via a malicious web page that triggers the CanvasWebGL component, although the official description does not explicitly state the vector.
OpenCVE Enrichment
Debian DLA
Debian DSA