Impact
An incorrect boundary check in the DOM animation component can corrupt memory when an attacker supplies crafted content. This off‑by‑one error leads to behavior such as memory corruption.
Affected Systems
Mozilla’s Firefox and Thunderbird are affected. All releases before version 156 contain the flaw; users must upgrade to Firefox 156 or later and Thunderbird 156 or later.
Risk and Exploitability
The EPSS score is less than 1 % and the flaw is not listed in the CISA KEV catalog, suggesting a low exploitation probability. The CVE description indicates that an incorrect boundary check in the DOM animation component can lead to memory corruption when crafted content is processed. Based on this, it is inferred that a local attacker might exploit the flaw by opening a malicious web page or email message, though the official description does not explicitly state the attack vector. The resulting memory corruption could lead to denial of service or application crash, and the high CVSS score of 9.8 places the vulnerability at high overall risk.
OpenCVE Enrichment