Impact
The vulnerability results from incorrect boundary checks in the Widget: Win32 component, which can enable a carefully crafted widget or code to escape the sandbox that normally isolates this component. The flaw is classified as a boundary‑violation issue (CWE‑501). As a result, code that operates only within the restricted widget context could potentially run with the privileges granted to the component, thereby reducing the effectiveness of the sandbox protection.
Affected Systems
The issue affects Mozilla Firefox versions earlier than 156 and earlier Earth‑Release versions (ESR) prior to 153.3, as well as Mozilla Thunderbird versions earlier than 156 and ESR versions prior to 153.3.
Risk and Exploitability
The CVSS score of 9.0 indicates a high severity assessment. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. No publicly released exploit variants are known, and the lack of listed exploitation activity further implies that active exploitation is not documented at this time. The potential impact is limited to environments that allow loading of widgets, and remediation should be prioritized if such usage is present.
OpenCVE Enrichment