Impact
This vulnerability allows read access to data stored in the browser’s IndexedDB storage that should not be exposed to the application. The flaw could lead to the disclosure of local user data that is persisted in the IndexedDB database by web applications. The weakness is classified as CWE‑200, indicating a failure to adequately protect information from unauthorized disclosure.
Affected Systems
Mozilla Firefox versions released before 153 and before ESR 140.13, as well as Mozilla Thunderbird versions released before 153 and before ESR 140.13, are vulnerable. Users running earlier releases of these products are at risk of data leakage unless the affected component has been patched.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level. The EPSS score of less than 1% suggests that exploitation is unlikely at present but is not impossible. Based on the description, it is inferred that an attacker would need local system or physical access to read the data directly, or would need to exploit a same‑origin web application that misuses IndexedDB. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA