Impact
A site isolation fault exists in the Networking: HTTP component, scoring 9.8 on the CVSS scale and labeled CWE-346 for improper validation against trusted criteria. The flaw potentially allows an attacker to influence the isolation mechanisms that separate web content, which could enable the compromise of data that is normally protected by site isolation. The official description does not detail specific exploit outcomes beyond the site isolation boundary and therefore the extent of possible data exposure or additional attack vectors is not explicitly defined by the CVE record.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird on all platforms are vulnerable when running versions older than Firefox 153 or ESR 140.13, and Thunderbird 153 or ESR 140.13. All other installed versions are considered fixed.
Risk and Exploitability
The CVSS score of 9.8 marks the issue as critical, but the EPSS score of less than 1% indicates that, as of now, the likelihood of real‑world exploitation is low. The vulnerability is not listed in CISA's KEV catalog. The CVE description does not provide a concrete attack vector; the most likely scenario inferred would be the delivery of crafted HTTP traffic that exploits the site isolation flaw on the client side.
OpenCVE Enrichment
Debian DLA
Debian DSA