Impact
The vulnerability allows an attacker to bypass built‑in network security mitigations in Mozilla's Networking component. By exploiting this flaw, malicious traffic could be routed through the application without triggering standard defenses, effectively granting the attacker the ability to conduct unauthorized network operations. This weakness is identified as CWE‑693, indicating improper control of a resource that requires authorization. An attacker could therefore compromise confidentiality or integrity of network communications or use the affected applications as a conduit for malicious payloads.
Affected Systems
Mozilla Firefox versions earlier than 153 and Thunderbird before 153 are affected. The flaw has been addressed in Firefox 153 and Thunderbird 153, so any installation of these products without the confirmed patch is at risk.
Risk and Exploitability
The CVSS score of 9.1 marks this as a critical vulnerability, while the EPSS score of less than 1% suggests that active exploitation in the wild is currently low but not impossible. The vulnerability is not listed in the CISA KEV catalog, meaning no known mass exploitation campaigns have leveraged it yet. Given the network‑based nature inferred from the description, attackers would likely need access to traffic passing through the affected applications, making the attack vector network‑remote. The combination of high severity and low current exploitation probability creates a pressure to patch promptly while remaining vigilant for suspicious network patterns.
OpenCVE Enrichment