Impact
The vulnerability located in Firefox's Address Bar component permits privilege escalation. An attacker could manipulate the component to elevate privileges within the browser, potentially allowing malicious code to run with higher authority than intended, thereby compromising user data and browser integrity.
Affected Systems
Mozilla Firefox, all releases prior to Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17 are affected. The fix was released in those specific patched versions, so any older or unpatched installations remain vulnerable.
Risk and Exploitability
The issue carries a CVSS score of 8.8, indicating high severity. EPSS information is not available, and it is not listed in CISA's KEV catalog. The likely attack vector is interaction with the Address Bar, such as entering a crafted URL or leveraging user-triggered input, which could lead to elevation of privileges for the browser process. Though the precise exploitation likelihood is uncertain due to missing EPSS data, the high CVSS score and the nature of the privilege escalation mean that exploitation would afford an attacker significant control over the affected system.
OpenCVE Enrichment