Impact
The use‑after‑free flaw exists in the Widget: Win32 component shipped with Mozilla Firefox and Thunderbird. After the component releases memory it still uses a dangling reference, allowing an attacker to read or write de‑allocated memory. This can ultimately lead to arbitrary code execution or application crashes, compromising confidentiality, integrity, and availability for any user running malicious input.
Affected Systems
Affected versions include Mozilla Firefox before 156 and the ESR line before 153.3, and Mozilla Thunderbird before 156. Any binary that bundles the Widget: Win32 component is vulnerable, including earlier ESR releases and custom builds that still contain the component.
Risk and Exploitability
The CVSS score of 8.8 shows high severity, and the EPSS score is less than 1% with no current KEV listing, so widespread exploitation is not yet evident. However, the likely attack vector is an attacker supplying crafted input that activates the component and triggers the dangling reference—such as a malicious web page, email attachment, or other user‑initiated action. Based on the description, it is inferred that remote exploitation is possible, giving the attacker application‑level privileges.
OpenCVE Enrichment