Impact
This vulnerability arises from incorrect boundary conditions in the WebRTC component, which allows an attacker to escape the application sandbox. The flaw manifests as a boundary‑checking bug that can be triggered by specially crafted data received through WebRTC. Escaping the sandbox can enable malicious code to run with the privileges of the browser or mail client, undermining the security model of the process isolation.
Affected Systems
Mozilla Firefox versions older than 156 and ESR releases before 153.3, as well as Mozilla Thunderbird versions older than 156 and ESR releases before 153.3 are affected. These releases contain the vulnerable WebRTC implementation and must be upgraded to the patched versions to eliminate the flaw.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity. The EPSS score of <1% suggests that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation via network traffic processed by WebRTC, requiring the presence of the vulnerable component and a remote connection. While the risk is high, the potential to escape a sandbox and undermine process isolation makes it a high‑impact flaw should an attacker find a way to trigger it.
OpenCVE Enrichment