Impact
An uninitialized memory bug in the Graphics: CanvasWebGL component can allow a malicious canvas or WebGL resource to cause the software to read or use data that has not been properly set, which may result in an elevation of privilege. The flaw is identified as CWE-457 and possibly CWE-824, and it can grant an attacker higher privileges on the device or allow them to access restricted data. The vulnerability is limited to the client application and targets the graphics engine processing canvas input.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The issue applies to all releases prior to Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. Users utilizing earlier versions may be vulnerable and need to update to the fixed releases.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector involves a local or remote attacker delivering a crafted canvas or WebGL resource to the target system. The CVSS score of 8.8 indicates a high severity level, while the EPSS score of <1% suggests a very low probability of widespread exploitation. The vulnerability is not listed in CISA KEV, and no publicly reported exploits are documented at this time.
OpenCVE Enrichment