Impact
The vulnerability is a use‑after‑free in the networking component of Mozilla Firefox and Thunderbird. It allows an attacker to corrupt memory by controlling network traffic or content, potentially leading to arbitrary code execution and full compromise of the affected system. The flaw represents a misuse of deallocated memory (CWE-416) and, additionally, relies on a resource exhaustion condition (CWE-825), which can subvert confidentiality, integrity, and availability.
Affected Systems
Mozilla Firefox and ESR 140.16 or later, Thunderbird and ESR 140.16 or later, and any versions prior to Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird ESR 140.16, and Thunderbird ESR 153.3 are vulnerable. The issue is recorded for the networking components of these products.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, reflecting a serious threat. The EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been observed. The most likely attack vector is remote, via malicious or potentially local network traffic that exploits the use‑after‑free flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA