Impact
A use‑after‑free flaw exists in the SVG component of Mozilla applications. The vulnerability arises when the rendering engine accesses memory that has already been freed, leading to memory corruption. While the description does not explicitly state the exact consequence, such conditions may allow an attacker to inject controlled data or potentially execute code within the user’s context.
Affected Systems
The flaw affects Mozilla Firefox and Mozilla Thunderbird. Versions before 156 of standard releases, or before ESR releases 115.41, 140.16, and 153.3, are vulnerable. Users should verify that they are running a fixed version of either browser or email client.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact. The EPSS is less than 1%, implying a very low but non‑zero likelihood that the flaw has been exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of malicious SVG content, either through a web page or a local file, which can trigger the use‑after‑free condition.
OpenCVE Enrichment
Debian DLA
Debian DSA