Impact
The vulnerability is a graphics component bug involving an invalid pointer that enables an attacker to spoof data. The flaw allows an attacker to forge identity or authenticity information, potentially misleading the user or other applications about the origin of graphic content. The impact is a spoofing attack that could undermine trust in displayed content without compromising system integrity or confidentiality.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The issue was addressed in Firefox 156 and Thunderbird 156. No other vendor or product versions are listed.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity. The EPSS score of < 1% and the lack of a KEV listing suggest that the likelihood of exploitation remains low in the current environment. Because the issue lies in the graphics component’s handling of an invalid pointer, it is inferred that an attacker would need to deliver crafted graphic content—such as a specially designed image or an HTML page referencing it—to trigger the bug on the target system. Exploitation would most likely require local or privileged execution, as no mechanism for remote code execution or privilege escalation has been reported.
OpenCVE Enrichment