Impact
This vulnerability arises from a flaw in the Service Workers component of Mozilla Firefox. The flaw enables malicious code executed within a service worker to obtain privileges that are typically reserved for trusted service workers – this inference is drawn from the designation of privilege escalation in the CVE entry. The elevated privilege level can be abused to access or modify sensitive user data, interfere with network traffic, or otherwise compromise the browser’s isolation guarantees. The weakness is classified as Improper Authorization (CWE‑269).
Affected Systems
All versions of Mozilla Firefox older than ESR 140.17, ESR 153.4, and the non‑ESR release 157 are affected. The vulnerability was fixed in those specific releases; any installation running an earlier version remains vulnerable. The impact applies to the local browser environment and can affect all authenticated user data and browsing sessions.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. Because an EPSS score is not available, the estimated likelihood of exploitation remains uncertain. The vulnerability is not listed in the CISA KEV catalog and no active exploits have been reported in known public channels. The flaw’s nature—privilege escalation within the browser—makes it particularly concerning for users who rely on service workers for web application functionality.
OpenCVE Enrichment