Impact
The flaw resides in the DOM Workers component and allows privilege escalation by enabling code to run with authority beyond the normal isolation limits. The vulnerability is associated with CWE-266, CWE-269, and CWE-284. An attacker who can supply or persuade a user to load malicious content could create a worker that gains elevated access to browser resources, potentially compromising all browsing activity.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird, all versions released prior to version 153. The issue was fixed in Firefox 153 and Thunderbird 153.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity; however the EPSS score of less than 1% indicates a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves a malicious web page or add‑on that creates a Web Worker with elevated privileges, requiring the user to load permissions.
OpenCVE Enrichment