Impact
A use‑after‑free flaw located in the JavaScript engine’s Just‑In‑Time (JIT) component can allow an attacker to corrupt memory after a freed object is reused. If an attacker can supply malicious JavaScript code that reaches the vulnerable JIT sub‑component, the flaw could lead to arbitrary code execution or a crash, compromising confidentiality, integrity.
Affected Systems
Affected systems are Mozilla Firefox and Mozilla Thunderbird. The flaw was fixed in Firefox ESR 140.16 and Thunderbird 140.16; versions prior to these contain the vulnerability.
Risk and Exploitability
The EPSS score is available and indicates a very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. Because the flaw the attack vector involves execution of crafted JavaScript, possibly delivered via web content or email attachments. The severity is high owing to its memory‑corruption nature, but the EPSS score suggests exploitation is unlikely. The updated CVSS score is 8.8.
OpenCVE Enrichment
Debian DLA
Debian DSA