Impact
The flaw arises from an invalid pointer reference in the Graphics component, which can be triggered by processing malformed or crafted graphics data. This memory corruption leads to a sandbox escape, allowing code to run with the same privileges as the host application. The vulnerability is associated with buffer overflow, null reference dereference, and out‑of‑bounds write weaknesses.
Affected Systems
Affected Mozilla releases include Firefox up to version 155, Firefox ESR 140.15/153.2, Thunderbird up to version 155, and Thunderbird ESR 140.15. The issue was fixed in Firefox 156, ESR 140.16, and ESR 153.3, as well as in Thunderbird 156, ESR 140.16, and ESR 153.3.
Risk and Exploitability
The EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.6 denotes a critical risk level. An attacker would most likely exploit the flaw by delivering a crafted graphics file or otherwise forcing the application to render untrusted visual content, thereby escaping the sandbox. Because the attack requires controlled rendering inside the sandbox, it is less easily achieved from a remote position but still feasible for local or privileged adversaries.
OpenCVE Enrichment
Debian DLA
Debian DSA