Impact
A malformed SVG file can trigger a denial‑of‑service condition, causing the application to abort or crash. The flaw is an input validation weakness that leads to resource exhaustion, matching the description for CWE-770. The incident would interrupt user sessions but does not provide confidentiality or integrity compromise.
Affected Systems
The issue affects Mozilla Firefox and Thunderbird browsers. Versions impacted include Firefox 156 and Firefox ESR 153.3, as well as Thunderbird 156 and Thunderbird 153.3, and earlier releases that remain vulnerable until they upgrade.
Risk and Exploitability
The exploit requires an attacker to deliver a specially crafted SVG to the target, likely through a web page or email attachment. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating opportunistic exploitation. With a CVSS score of 6.5, the risk is moderate; the flaw causes crashes but the likelihood of exploitation remains low.
OpenCVE Enrichment