Impact
The vulnerability is a use‑after‑free bug in the JavaScript WebAssembly component. This flaw can corrupt memory, allowing arbitrary reads or writes. The official description does not specify the precise consequences, so while the CVSS score of 8.8 indicates high severity, it is inferred that the memory corruption could be exploited to alter execution or destabilize the system.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird versions older than 156 are vulnerable; the issue was addressed in Firefox 156 and Thunderbird 156.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. Based on the description, it is inferred that the attack vector likely involves a malicious web page or email that triggers the buggy WebAssembly component. The high CVSS score of 8.8 combined with the low exploitation probability indicates a significant but not imminent risk for affected users.
OpenCVE Enrichment