Impact
The reported flaw is an incorrect boundary condition in the Security: Process Sandboxing component, classified as CWE‑403. It also aligns with CWE‑119, indicating a failure to enforce correct buffer boundaries. This weakness permits malicious code or data to cross the intended sandbox barrier, potentially enabling a sandbox escape. The primary consequence is that a confined process could gain the privileges of the host system, thereby compromising confidentiality, integrity, or availability of the affected application.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are impacted. All releases prior to Firefox 156 and Thunderbird 156 contain the vulnerability; the issue was addressed in those version releases.
Risk and Exploitability
The overall CVSS score of 9.8 denotes high severity, and the EPSS score of < 1 % indicates a very low probability of exploitation. The vulnerability is not part of the CISA KEV list. While a sandbox escape could lead to remote code execution if an attacker supplies malicious content to the vulnerable application, there is no publicly documented exploit and the risk of successful exploitation remains low at present.
OpenCVE Enrichment