Impact
The vulnerability permits malicious extensions or web scripts to read or manipulate data from origins that are normally protected by the browser’s same‑origin policy. An attacker who can exploit this flaw can exfiltrate sensitive information, inject rogue content, or potentially execute arbitrary code in the user’s context, thereby compromising confidentiality, integrity, and possibly availability of the affected system.
Affected Systems
The flaw affects Mozilla Firefox browsers. Versions released before Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17 are vulnerable. All earlier non‑ESR releases lacking these specific patch builds are also impacted, meaning users on older Firefox versions must upgrade to a build equal to or newer than the stated ESR or desktop releases.
Risk and Exploitability
Because the CVSS score is not provided and the EPSS score is unavailable, the precise risk level cannot be quantified numerically. The vulnerability is listed as not in KEV, indicating no known large‑scale exploits at present, but the nature of a same‑origin policy bypass suggests it is a high‑severity concern suitable for rapid remediation. The attack vector is most likely local, through the installation of a malicious or compromised browser extension that can trick the WebExtensions component into granting cross‑origin access. Advisors describe the fix as released in specific ESR and desktop builds.
OpenCVE Enrichment