Impact
Sandbox escape due to incorrect boundary conditions in the Graphics component. Because the graphics engine performs insufficient boundary checks, it may access memory beyond intended limits, potentially allowing an attacker to escape the sandbox and execute arbitrary code outside the confined application.
Affected Systems
All Mozilla Firefox releases earlier than 156 and all Firefox ESR releases earlier than 153.3, 115.42, and 140.17 are affected, as are all Mozilla Thunderbird releases earlier than 156 and Thunderbird 140.17. The issue has been fixed in Firefox 156, Firefox ESR 153.3, 115.42, and 140.17; Thunderbird 140.17, 153.3, and 156.
Risk and Exploitability
Based on the description, the likely attack vector is remote exploitation through malicious graphics data supplied to the rendering process. The CVSS score of 9.6 indicates critical severity, while the EPSS score of <1% suggests low current exploitation probability. This vulnerability is a sandbox escape that could enable an attacker to execute arbitrary code and gain privileges beyond the confined application. Although it is not listed in the CISA KEV catalog, no widespread exploitation has been reported yet; the inherent risk remains high due to the potential for privilege escalation. The low EPSS does not diminish the potential impact if an attacker crafts malicious graphics.
OpenCVE Enrichment
Debian DLA
Debian DSA