Impact
The vulnerability permits a bypass of DOM‑level mitigations in the Service Workers component. This weakness can allow malicious web content to circumvent the usual security boundaries imposed by the browser's Service Worker implementation. The effect is a relaxation of the sandbox that may expose sensitive operations or resources to the attacker. The CVE does not claim that arbitrary code execution is possible, but the removal of these controls is a serious breach of intended isolation.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. All releases older than Firefox 153 or Thunderbird 153 contain the flaw. Users on those earlier builds are at risk until they upgrade to the patched 153 or later versions.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity, yet the EPSS score of less than 1 % suggests a low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, with malicious web content that registers a Service Worker to benefit from the bypassed mitigations.
OpenCVE Enrichment