Impact
A flaw in the Graphics: ImageLib component allows an attacker to read private data embedded in image files. The vulnerability can expose sensitive information, compromising confidentiality, and is identified as a CWE-200 information exposure weakness as well as a CWE-497 issue.
Affected Systems
Mozilla products Firefox and Thunderbird are affected, with the issue present in versions prior to Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact, and the EPSS score of 0.00156 (less than 1%) indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV, which suggests a limited likelihood of widespread exploitation. The most probable attack vector is the processing of malicious image files by a compromised or user‑controlled application, a scenario component. No specific exploitation prerequisites are documented, but the absence of a publicly available exploit and limited exposure reduce the immediate risk for most users.
OpenCVE Enrichment
Debian DLA
Debian DSA