Impact
The vulnerability allows a malicious WebExtension to obtain system privileges exceeding those normally granted to extensions. This is an improper privilege escalation flaw, classified as CWE-266 (Improper Privilege Management) and CWE-269 (Improper Privilege Escalation). An attacker can run arbitrary code with elevated rights, read or modify sensitive data, and potentially bypass other browser security controls.
Affected Systems
Mozilla Firefox versions prior to 153 and Firefox ESR prior to 140.13, and Mozilla Thunderbird prior to 153 and Thunderbird ESR prior to 140.13 are affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, while an EPSS score of less than 1 % signals a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector involves installing or loading a malicious WebExtension, whether signed or unsigned, after which the extension can elevate its own privileges on the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA