Impact
A vulnerability in the Firefox DevTools component allows an attacker to bypass the browser’s same‑origin policy, potentially exposing cross‑origin data or executing code across site boundaries. The flaw permits unauthorized access to resources that should be protected by the same‑origin restrictions, which could lead to data leakage, session hijacking, or execution of malicious content in a trusted context. The vulnerability is a direct result of improper authorization handling within the DevTools subsystem.
Affected Systems
Mozilla Firefox is affected, with the fix applied in Firefox ESR 153.4 and Firefox 157. Versions prior to these releases are potentially vulnerable. No specific lower bound is listed, so any build before the mentioned versions should be considered at risk.
Risk and Exploitability
No CVSS score is provided in the data, and the EPSS score is not available, making it difficult to quantify exact risk quantitatively. The CVE is not listed in the CISA KEV catalog, indicating no known public exploits at the time of the advisory. The likely attack vector is local: a user or local script that can access DevTools may exploit the flaw to read or modify cross‑origin information. The bypass could be used to exfiltrate data or inject malicious payloads if the attacker can drive user interaction with the DevTools interface. Given the nature of a same‑origin policy failure, the potential impact could be high if an attacker can co‑ordinate the exploit with compromised content or phishing pages.
OpenCVE Enrichment