A use-after-free vulnerability in the Skia library can occur when creating a path, leading to a potentially exploitable crash.
An integer overflow vulnerability in the Skia library can occur after specific transform operations, leading to a potentially exploitable crash.
A buffer overflow vulnerability in the Skia library can occur with Canvas 2D acceleration on macOS. This issue was addressed by disabling Canvas 2D acceleration in Firefox ESR.
Note: this does not affect other versions and platforms where Canvas 2D acceleration is already disabled by default.