Impact
A flaw in the DOM networking component allows a bypass of the standard mitigation that normally protects web content. The vulnerability can be leveraged by an attacker to override security checks, potentially enabling the execution of malicious code or other actions that would ordinarily be blocked. The weakness corresponds to CWE‑693 (Security Misconfiguration) and CWE‑807 (Use of Exception to Control Flow) and is represented by a CVSS score of 9.8, indicating a critical threat to confidentiality, integrity, and availability.
Affected Systems
Mozilla Firefox and Thunderbird are affected. Any release prior to Firefox 153, Firefox ESR 140.13, Thunderbird 153, or Thunderbird ESR 140.13 contains the flaw, so users running those older versions must update.
Risk and Exploitability
The high CVSS score reflects the ability to bypass fundamental mitigations, but the EPSS score of less than 1 % suggests that, as of now, exploitation likelihood is very low. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve malicious web content or extensions that manipulate the DOM within the networking component.
OpenCVE Enrichment
Debian DLA
Debian DSA