Impact
A use‑after‑free flaw exists in the DOM HTML parser component, allowing an attacker to corrupt memory when the parser processes malicious input. This memory corruption can potentially compromise the confidentiality, integrity, or availability of the affected process, and is categorized as CWE-416 and CWE-825.
Affected Systems
The vulnerability affects all Mozilla Firefox and Thunderbird releases prior to the fixed versions. This includes Firefox 156 and all earlier releases, as well as ESR branches older than 115.41, 140.16, and 153.3. Thunderbird is affected up to and including version 156, and ESR branches older than 140.16 and 153.3.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity level, while the EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could supply crafted HTML content—such as in a malicious web page or email—to trigger the flaw, leading to memory corruption. No publicly disclosed exploit exists currently, but the high severity warrants prompt attention.
OpenCVE Enrichment
Debian DLA
Debian DSA