Impact
A use‑after‑free flaw exists in the graphics component of Firefox and Thunderbird. The flaw permits an attacker to corrupt memory after the original object has been freed, which could allow the execution of arbitrary code. This vulnerability undermines confidentiality, integrity, and availability of the affected system if successfully exploited.
Affected Systems
Mozilla publishes this vulnerability for Firefox versions before 156 and Firefox ESR before 153.3, as well as Thunderbird before 156 and Thunderbird ESR before 153.3. Users running any of these outdated releases are impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation. Although the use‑after‑free flaw permits arbitrary code execution, the exploit probability remains low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and would be triggered through crafted graphics data delivered via web pages or email attachments that are processed by the victim’s application.
OpenCVE Enrichment