CVE-2023-4577

Publication date

2023-09-11 08:01:02

Family

mozilla

State

PUBLISHED

Description

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.