Impact
Use‑after‑free within the Gtk widget used by Mozilla applications can corrupt memory, potentially allowing an attacker to execute arbitrary code or elevate privileges in the context of the user. The flaw is classified as a high‑severity vulnerability with a CVSS score of 8.8, meaning it can lead to severe impact beyond a simple crash. The underlying weakness, a use‑after‑free, is listed as CWE‑416, and its misuse in rendering can also trigger a denial of service.
Affected Systems
The affected products are Mozilla Firefox and Mozilla Thunderbird. All releases older than Firefox 156, Firefox ESR 153.3, and Thunderbird 156 are susceptible. Users running versions before these releases should consider them vulnerable until the recommended update is applied. No specific operating system or platform is singled out; the flaw resides in the Gtk component shared across all supported platforms.
Risk and Exploitability
The likelihood of exploitation remains low, with an EPSS score of <1% and absence from the CISA KEV catalog. However, the vulnerability’s high CVSS score highlights its potential severity if exploited. The most probable attack vector is delivery of malicious content or a compromised plugin that triggers the Gtk widget, causing the use‑after‑free and leading to arbitrary code execution or a crash. Successful exploitation would grant the attacker code execution rights within the user’s session, or potentially higher privileges if privilege escalation paths exist. The exploitability requires that the client application parse the malicious content; no special operating‑system or privilege prerequisites are indicated in the advisories.
OpenCVE Enrichment