Impact
The vulnerability is defined as a mitigation bypass within the DOM‑based networking component of Mozilla Firefox and Mozilla Thunderbird. It is classified as CWE‑693, indicating a failure of a protection mechanism. The official advisory does not articulate a particular defense or data that could be compromised, so the exact consequence of the flaw remains unspecified. Based on the description, it is inferred that the flaw could allow an attacker to bypass network‑level mitigations normally enforced by the browser.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird versions earlier than 153 are affected. The flaw was fixed in Firefox 153 and Thunderbird 153. No older or newer versions are claimed to be vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity. The EPSS score is below 1 %, indicating a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely observed. The advisory does not provide an explicit attack vector; thus it remains unclear whether remote or local conditions are required. No definitive exploitation path is documented, so impact scope is uncertain.
OpenCVE Enrichment