Impact
Use‑after‑free bug in Mozilla Firefox and Thunderbird’s DOM core and HTML processing can corrupt heap memory when arbitrary content is rendered, which may allow an attacker to execute code within the client process or cause it to terminate, impacting confidentiality, integrity, or availability.
Affected Systems
Vulnerable on all Firefox and Thunderbird releases before 156, including ESR 115.41, 140.16, 153.3. The fix is shipped in Firefox 156 and the corresponding ESR releases, and in Thunderbird 156 and the ESR 140.16 and 153.3 releases.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The EPSS score of less than 1 % suggests a low current likelihood of exploitation. The vulnerability is not in CISA’s KEV catalog. The likely attack vector is delivered through malicious web content that triggers the bug; based on the description, it is inferred that an attacker must supply crafted content that drives the renderer into the vulnerable code path.
OpenCVE Enrichment
Debian DLA
Debian DSA