Impact
This vulnerability is a use‑after‑free flaw in the Graphics: Text component of Mozilla applications. The flaw corresponds to CWE-416. The corruption of memory can lead an attacker to crash the application or, depending on the conditions, execute arbitrary code. The official description does not explicitly confirm code execution, so that possibility is inferred from the typical effects of a use‑after‑free bug.
Affected Systems
The flaw affects Mozilla Firefox versions older than 156 and Firefox ESR 153.3, as well as all Thunderbird releases prior to 156 and pre‑ESR 153.3. Users running these legacy versions remain at risk until the provided fixes are applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity assessment, and the EPSS score is under 1%, which suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack would likely require an attacker to cause the application to render malicious content, such as a specially crafted web page or document, indicating a content‑based remote or local vector. If exploitation succeeds, the attacker could crash the application or potentially execute arbitrary code, though the latter is inferred and not explicitly documented in the advisory.
OpenCVE Enrichment