Impact
A race condition within Mozilla’s DOM Content Processes component can cause rendering processes to enter an inconsistent state, potentially leading to application crashes. The vulnerability is identified as a race condition (CWE-366 and CWE-362 affecting process stability and user experience).
Affected Systems
The issue impacts both Mozilla Firefox and Mozilla Thunderbird. All releases prior to Firefox 156, Thunderbird 156, and the Firefox ESR 153.3 build are affected. Users running any of those older versions without the respective fixes are susceptible.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered high severity. The EPSS score is <1%, indicating a very low probability of exploitation. It is not listed in CISA’s KEV catalog. While the description does not specify an explicit attack vector, the race condition could potentially be triggered by malicious content served to the browser or local files, but no public exploit is known.
OpenCVE Enrichment