Impact
The vulnerability is a privilege‑escalation flaw in the DOM Workers component of Mozilla products, allowing code to run with elevated authority beyond normal isolation boundaries. It is classified under CWE‑266 (Improper Privilege Management), CWE‑269 (Improper Privilege Removal), and CWE‑284 (Improper Access Control). The flaw could be used by a malicious web page or add‑on to gain higher privileges than intended within the browser context.
Affected Systems
All Mozilla Firefox releases before version 153, all Mozilla Thunderbird releases before 153, and the ESR releases Firefox 140.15 and Thunderbird 140.15 are affected. The vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird ESR 140.15.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, yet the EPSS score of less than 1% suggests a very low current likelihood of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector involves a malicious web page or extension that creates a Web Worker with elevated privileges, requiring user interaction or permission to load the content.
OpenCVE Enrichment
Debian DLA
Debian DSA