Impact
Sandbox escape in the XUL component allows code executing in a sandboxed process to break out of its confinement and run with elevated privileges. An attacker could exploit this flaw to execute arbitrary code or upgrade privileges, potentially compromising the entire system. The weakness aligns with improper privilege management as the sandbox boundaries are not correctly enforced.
Affected Systems
All Mozilla Firefox releases before ESR 153.4 and all mainline Firefox versions before 157 are affected. The exact version range is not detailed in the advisory, but the vulnerability has been fixed by those releases, implying earlier versions contain the flaw. The issue impacts the XUL component used by Firefox.
Risk and Exploitability
Because the flaw enables sandbox escape, it could be leveraged by malicious web content or compromised extensions to elevate privileges. The attack vector is inferred to be local, triggered by a user visiting a malicious site or running a malicious extension. No EPSS or CVSS scores are available, and the vulnerability is not listed in CISA's KEV catalog, so the exploitation probability is unknown, yet given the potential for complete system compromise, the risk remains high. Administrators should treat this as a high‑priority concern until a patch is applied.
OpenCVE Enrichment