Impact
Use-after-free in the SVG component corrupts memory after an attacker triggers a crash, thereby potentially compromising the confidentiality, integrity, and availability of the affected application.
Affected Systems
Mozilla Firefox (all releases prior to 156 and the ESR branches 115.41, 140.16 and 153.3) and Mozilla Thunderbird (all releases prior to 156 and the ESR branches 140.16 and 153.3) are affected.
Risk and Exploitability
The vulnerability is not listed in CISA KEV and has an EPSS score of < 1%, indicating a very low likelihood of exploitation. The CVSS score of 8.8 indicates high severity. Although no public exploits are known, the potential for code execution remains and the modest exploitation probability warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA