Impact
A flaw in the networking component of Mozilla products allows an attacker to escape the browser sandbox, potentially allowing unauthorized access to system resources. The bug is a security misconfiguration (CWE‑693) that undermines the isolation guarantees of the web content engine.
Affected Systems
The vulnerability was addressed in Firefox 153 and Thunderbird 153. Users running earlier releases expose their systems to the risk.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity. However, the EPSS score of < 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require a malicious web page or crafted network traffic that triggers the vulnerable networking component, suggesting a remote attack vector.
OpenCVE Enrichment