Impact
The vulnerability is a use‑after‑free flaw located in the graphics component of both Mozilla Firefox and Thunderbird. An attacker could trigger the flaw by causing the application to access freed memory, potentially corrupting program state or causing it to behave unpredictably. The official description specifies that the defect was fixed in later releases but does not state whether it could lead to privilege escalation or arbitrary code execution.
Affected Systems
Based on the fixed-in versions it can be inferred that Firefox 155 and earlier, Firefox ESR 153.2 and earlier, and Thunderbird 155 and earlier are affected. The security update targeting Firefox 156 / ESR 153.3 and Thunderbird 156 removes the flaw.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score of 0.15% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and there is no current evidence of exploitation. Attack vector details and exploitation conditions are not provided, so the exact method attackers could use remains unspecified. Given the potential for memory corruption, the risk could impact confidentiality, integrity, or availability of the affected systems.
OpenCVE Enrichment