Impact
Firefox contains a flaw in its navigation component that permits the browser’s site isolation mechanism to be bypassed. The bug may allow an attacker to force a navigation that crosses origin boundaries, thereby granting access to or reading data from another browsing context that should remain isolated. The vulnerability is consistent with CWE‑501, and its current CVSS score of 5.4 indicates moderate severity. Since publicly available exploit code exists but no attacks are reported in the wild, the risk is primarily theoretical.
Affected Systems
Mozilla Firefox builds that have not yet received the patch in version 152.0.6, ESR 115.38, or ESR 140.13, and Mozilla Thunderbird builds that have not yet been updated to version 140.13 may be impacted, but the vendor does not specify an exact affected version range.
Risk and Exploitability
The EPSS score of less than 1% points to a very low probability of exploitation under current conditions, and the vulnerability is not listed in CISA KEV. The likely attack vector is a maliciously crafted web page that triggers navigation across isolation boundaries, potentially exploiting lack of user interaction or unsuspecting user engagement. With no recorded incidents, the threat remains unproven but possible if an attacker can leverage the public exploit code.
OpenCVE Enrichment
Debian DLA
Debian DSA