Impact
A use‑after‑free bug exists in the Streams component of the browser’s DOM engine. When a stream object is released while references to it still exist, the browser can read or write memory outside the allocated space. This leads to memory corruption that could be leveraged to execute arbitrary code or crash the application. The flaw maps to the improper handling of freed resources and arbitrary writes due to use‑after‑free vulnerabilities (CWE‑825, CWE‑416).
Affected Systems
All Mozilla Firefox releases before version 156 and all ESR releases older than 115.41, 140.16, and 153.3 are affected. For Mozilla Thunderbird, any release older than 156 and ESR versions before 140.16 and 153.3 also have the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 classifies it as high severity. The EPSS score of less than 1 % indicates a very low but non‑zero exploitation likelihood, and it is not listed in the CISA KEV catalog. Attackers would typically deliver malicious web content or streamed data that triggers the stream logic while the browser is running, exploiting the dangling reference. Successful exploitation could corrupt memory, potentially leading to arbitrary code execution or a denial‑of‑service condition.
OpenCVE Enrichment
Debian DLA
Debian DSA