Impact
The flaw is a use‑after‑free defect in the Internationalization component of Mozilla Firefox and Thunderbird. When locale data that can be influenced by an attacker is processed, the component frees an object and later accesses the same memory location, which can corrupt the heap. The corruption may change program state, but the description does not guarantee arbitrary code execution or the ability to bypass access controls. The weakness is listed as CWE‑416 and CWE‑825 and reflects a classic memory‑management error.
Affected Systems
This vulnerability applies to all releases of Mozilla Firefox and Mozilla Thunderbird that precede Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3. Users running any earlier version that processes locale or internationalization data are at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1 % signals a very low probability of exploitation in the wild. The vulnerability is not present in the CISA KEV catalog, meaning no confirmed active exploits have been reported. Attackers would need to deliver crafted locale or internationalization data, likely via a local file or user‑controlled input, to trigger the flaw. Given the low exploitability metrics, the risk to broad audiences is limited.
OpenCVE Enrichment