Impact
Incorrect boundary checks in the WebRender component of the Graphics subsystem result in a buffer overrun and an out‑of‑bounds write. A malicious user can supply oversized data that corrupts memory and gains arbitrary code execution in the browser or mail client. This flaw allows a local privilege escalation, enabling an attacker to read, modify, or delete local files, install malware, or otherwise take full control of the victim’s machine. The weakness is identified as a classic buffer overrun (CWE‑120) and an out‑of‑bounds write (CWE‑787).
Affected Systems
Mozilla’s Firefox web browser and Thunderbird mail client are affected. Any release prior to Firefox 156, Firefox ESR 115.41, 140.16, 153.3 and Thunderbird 156 or ESR 140.16 contains the vulnerability. Current official releases contain the fix, so systems still using older builds remain at risk until updated.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of <1% shows a very low exploitation probability, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local: a malicious web page or mail attachment can trigger the flaw by feeding oversized data to the WebRender subsystem. If successful, the attacker gains code execution with the privileges of the user profile, effectively elevating privileges and compromising the entire local environment.
OpenCVE Enrichment
Debian DLA
Debian DSA