Impact
The vulnerability resides in the Enterprise Policies component and permits a bypass of the mitigation controls specified by the system. This ability to override or circumvent policy settings could undermine the intended security posture, although the description does not specify any additional capabilities such as code execution. The flaw corresponds to CWE-693, involving insufficient verification of policy authenticity.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Any installation of Firefox older than version 153 or ESR 140.13, and any installation of Thunderbird older than version 153 or ESR 140.13, remains vulnerable, as the fix was introduced in those releases.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity flaw, and the EPSS score of less than 1% shows a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to deliver a malicious policy file or manipulate existing policy configurations to trigger the bypass, but the exact attack vector is not described in the advisory.
OpenCVE Enrichment
Debian DLA
Debian DSA