Impact
An use‑after‑free flaw exists in the XML component or crafted XML, leading to memory corruption which may cause application instability or compromise the integrity of the affected process.
Affected Systems
Mozilla Firefox and Thunderbird releases before Firefox 156, Firefox ESR 115.41, 140.16, or 153.3 and before Thunderbird 156 or Thunderbird ESR 140.16. The flaw has been fixed in those patched versions and subsequent releases.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the bug is not listed in the CISA KEV catalog. Because the description does not specify how the flaw is triggered, the likely attack vector is inferred to be a remote delivery of malicious XML content—such as via a web page, email attachment, or any other untrusted source that forces the client to parse XML. Even without documented public exploitation, an attacker could potentially exploit the affected process to cause instability or memory corruption.
OpenCVE Enrichment
Debian DLA
Debian DSA