Impact
The vulnerability is an information‑disclosure flaw in the Framework component of DevTools, which can expose sensitive data to an attacker. The flaw is classified as CWE‑200 and allows an attacker to read data that should be protected, such as files, environment variables, or network traffic captured by DevTools. The potential consequences are loss of confidentiality for the user or compromised application data. Based on the description, the vulnerability is likely exploitable by an attacker who can access the DevTools environment, for example a local user who has control over the browser process or who can initiate a remote debugging session.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected, including both the standard releases and the ESR channel. The fix is implemented in Firefox 153, Firefox ESR 140.13, Thunderbird 153 and Thunderbird ESR 140.13. All earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact that does not meet the highest severity but still requires attention. The EPSS score of less than 1% shows that real‑world exploitation is expected to be rare, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or via a compromised remote debugging session; additional conditions such as the attacker having access to the DevTools interface are required. The combination of a moderate exploitation probability and high confidentiality impact suggests a prudent approach to mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA