Impact
This flaw permits a malicious web page to break the site isolation barrier enforced by the WebRender graphics engine, enabling the attacker to read rendered output from a page that it does not control. The vulnerability is identified as CWE-346 and CWE-368. Because the flaw allows information leakage rather than arbitrary code execution, the primary consequence is a breach of user privacy and integrity of data displayed on other sites.
Affected Systems
Vulnerable versions are those of Mozilla Firefox and Mozilla Thunderbird released before the fixes. The issue was addressed in Firefox 153, and in the ESR branches 115.38 and 140.13 as well as in Thunderbird 153 and its ESR 140.13. Any earlier build is affected.
Risk and Exploitability
The CVSS score of 9.8 signals a very high severity. The EPSS score of less than 1% indicates that active exploitation at present is unlikely, and the vulnerability is not present in CISA’s KEV catalog. The likely attack vector is a malicious web page forcing the browser to use WebRender; an attacker could read or infer content from other sites that share the rendering process.
OpenCVE Enrichment
Debian DLA
Debian DSA