Impact
The flaw is a use‑after‑free within the Disability Access APIs component. After an API call frees an object, the application may later dereference the same memory address, leading to memory corruption. If an attacker can trigger the vulnerable sequence, it could enable arbitrary code execution or cause a denial of service.
Affected Systems
Mozilla Firefox versions earlier than 156, Firefox ESR versions earlier than 140.16 or 153.3, Thunderbird versions earlier than 156, Thunderbird ESR versions earlier than 140.16 or 153.3, all operating systems for which those browsers are available.
Risk and Exploitability
The CVSS score of 8.8 indicates the vulnerability is considered high severity, but the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to exploit the Disability Access APIs, possibly via crafted web content or a local action that triggers the freed memory reuse; the exact vector is not publicly defined, so a cautious approach is required.
OpenCVE Enrichment
Debian DLA
Debian DSA