Impact
The vulnerability is a graphics component bug involving an invalid pointer that enables an attacker to spoof data. The flaw allows an attacker to forge identity or authenticity information, potentially misleading the user or other applications about the origin of graphic content. The impact is a spoofing attack that could undermine trust in displayed content without compromising system integrity or confidentiality.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The issue was addressed in Firefox 156 and Thunderbird 156. No other vendor or product versions are listed.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score of < 1% and lack of a KEV listing indicate that exploit likelihood is currently low and the vulnerability has not been observed in the wild. An attacker would likely need local or privileged access to leverage the pointer misuse in the graphics engine to generate forged content. The threat remains theoretical until a proof‑of‑concept or exploit is publicly released.
OpenCVE Enrichment