Impact
A use-after-free flaw exists in the graphics component of Firefox and Thunderbird. The flaw allows an attacker to corrupt memory after the original object has been freed, potentially enabling the execution of arbitrary code. Because the vulnerability can affect both the browser and mail client, it can compromise confidentiality, integrity, and availability of the affected system if exploited successfully.
Affected Systems
Mozilla publishes this vulnerability for Firefox versions before 156, Firefox ESR before 153.3, and Thunderbird before 156. Users running any of these outdated releases are impacted.
Risk and Exploitability
The CVSS score is not provided, and no EPSS value is available, but the nature of a use-after-free typically signals a high severity risk. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, triggered through rendered web or email content that exercises the graphics component. The conditions for exploitation would require the attacker to supply crafted graphical data that is processed by the victim’s application.
OpenCVE Enrichment