Impact
The vulnerability involves the DOM copy‑and‑paste and drag‑and‑drop components of Firefox and Thunderbird. An attacker could manipulate or inject data during clipboard operations. While the CVE entry does not state which data types are affected, it can be inferred that the altered or injected content might be processed by the application.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird versions earlier than 153 are vulnerable. Users running these older releases could be exposed until they upgrade to the fixed version.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity, but its EPSS score is below 1%, suggesting a low probability of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is not explicitly stated, but the nature of the flaw implies it could be triggered via local user interactions, such as a malicious web page or email that uses copy, paste, or drag‑and‑drop operations; this inference is based solely on the description of the component affected.
OpenCVE Enrichment