Impact
The flaw lies in the DOM Notifications component of Mozilla Firefox and Thunderbird. It allows a malicious web page that invokes the Notifications API to bypass normal access controls and elevate its privileges within the browser’s execution context. Based on the description, it is inferred that the attacker can exploit the bug simply by hosting a site that triggers a notification request, thereby gaining higher privileges that can affect the local user’s data or enable additional malicious behaviour.
Affected Systems
Mozilla Firefox versions older than 146, Firefox ESR releases older than 115.31 and 140.6, Mozilla Thunderbird versions older than 146, and Thunderbird ESR releases earlier than 140.6 are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% indicates a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious site that invokes the Notifications API, exploiting insufficient validation or permissions within the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN