Impact
An flaw in the Networking: DNS component lets a user bypass the browser’s same‑origin policy, granting access to DNS responses that should otherwise be restricted. This weakness is identified as CWE‑346.
Affected Systems
Both Mozilla Firefox and Thunderbird disclose this vulnerability in versions released before the immediate fixes, which are Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. Users of earlier releases remain vulnerable.
Risk and Exploitability
The CVSS score of 9.1 marks it as critical. By the EPSS score of less than 1 %, the likelihood of exploitation is low. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker might leverage malicious DNS responses to trigger the bypass when a victim’s browser processes those replies.
OpenCVE Enrichment
Debian DLA
Debian DSA