Impact
A flaw in the Panning and Zooming component of Firefox allows a web page to bypass the browser’s site isolation protections, potentially exposing data or code belonging to other web origins. This weakness can lead to unintended data leakage or cross‑origin instrumentation, but it does not grant direct code execution. The underlying deficiency is a failure to maintain proper isolation boundaries within the rendering engine.
Affected Systems
Mozilla Firefox users running versions prior to Firefox 157, or ESR releases older than ESR 153.4, ESR 115.42 or ESR 140.17, are vulnerable. The issue is fixed in those releases and later versions; updating to any of those builds removes the flaw.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is unknown. No active exploits have been reported, but a malicious site could trigger the bug by manipulating page panning or zooming, exploiting the bypass of site isolation. Given the potential for sensitive data exposure and the lack of readily known mitigations, the vulnerability should be treated as high risk until a confirmed patch or workaround is deployed.
OpenCVE Enrichment