Impact
This flaw permits malicious web content to invoke the DOM navigation component in a way that bypasses the browser’s same‑origin policy, exposing data normally confined to one origin. The flaw is classified as CWE‑346, an information exposure through a same‑origin policy violation. An attacker could thus read cookies, local storage, or other origin‑restricted information from the victim’s browser or email client without requiring operating‑system privileges. The likely attack vector is a crafted web page or email that causes the victim’s software to navigate via the vulnerable component; this inference follows from the description that the issue concerns navigation in the DOM.
Affected Systems
Mozilla Firefox versions older than 153, as well as the ESR builds before 115.38 and 140.13, and Mozilla Thunderbird versions earlier than 153 or ESR builds before 140.13 are impacted; the vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Risk and Exploitability
The CVSS score of 9.8 marks this as a severe vulnerability, while an EPSS score below 1 % indicates a low probability of large‑scale exploitation at present. It is not listed in the CISA KEV catalog, meaning no confirmed public exploits exist. The most probable exploitation path involves a malicious web page or email that triggers the vulnerable navigation component, allowing the attacker to read cross‑origin data. Monitoring and limiting navigation to trusted origins can reduce risk in the meantime.
OpenCVE Enrichment
Debian DLA
Debian DSA