Impact
Firefox and Thunderbird contain a vulnerability that allows attackers to bypass DOM‑based mitigation mechanisms. This weakness, identified as CWE‑693, enables the compromise of the intended security model of the application. Although the detailed exploitation impact is not explicitly described, the bypass could lead to unauthorized actions or data exposure within the affected client. The vulnerability was patched in version 153 of both products.
Affected Systems
All Mozilla Firefox and Thunderbird releases prior to version 153 are affected. The fix was introduced in Firefox 153 and Thunderbird 153, so any higher version is considered safe.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity, while the EPSS < 1% shows that exploitation probability is currently low. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through client‑side content such as a malicious web page or email, which can trigger the DOM mitigation bypass. No specific prerequisites are mentioned, so widespread use of older Firefox or Thunderbird versions exposes users to this risk.
OpenCVE Enrichment