Impact
The vulnerability is a site isolation flaw in the Networking component that could allow a malicious web page or attacker‑controlled network traffic to bypass isolation boundaries, potentially exposing sensitive data or gaining unauthorized access to privileged resources. This flaw maps to CWE-200, CWE-284, CWE-346, and CWE-501, indicating information disclosure, improper access control, client‑side request forgery, and user interface interaction problems.
Affected Systems
Mozilla Firefox versions older than 153 and ESR 140.13, and Mozilla Thunderbird versions older than 153 and ESR 140.13, are affected. The issue was fixed in Firefox 153 (and ESR 140.13) and Thunderbird 153 (and ESR 140.13).
Risk and Exploitability
The CVSS score is 9.8, signifying a critical severity. The EPSS score is less than 1%, indicating a very low but nonzero likelihood of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need to serve a malicious site or manipulate network traffic to trigger the flaw, indicating a remote attack possible from any location with network access to the affected client.
OpenCVE Enrichment
Debian DLA
Debian DSA