Impact
The flaw arises from incorrect boundary checks in the Graphics: CanvasWebGL component that is used by Mozilla Firefox and Thunderbird. When WebGL data exceeds expected limits, the component can allow the browser to elevate privileges within its own process. An attacker could exploit this to execute arbitrary code with the rights of the browser process, potentially abusing other weaknesses that coexist in the same environment. The weakness aligns with CWE‑120 (Buffer Assignments with Incorrect Length or Size) and CWE‑787 (Out‑of‑Bounds Write).
Affected Systems
All Mozilla Firefox releases older than version 156, including every ESR release before 115.41, 140.16 or 153.3, are vulnerable. The same applies to Mozilla Thunderbird versions older than 156, including all ESR releases before 140.16 or 153.3.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Based on the role of the component in rendering WebGL content, the most likely attack vector is a malicious WebGL payload delivered through a compromised or phishing website; this inference is based on the component’s handling of WebGL data, although the advisory does not explicitly describe the delivery method.
OpenCVE Enrichment
Debian DLA
Debian DSA