Impact
The reported vulnerability is a site isolation issue in the Graphics component of Mozilla Firefox and Thunderbird. It allows a malicious web page or context to read or manipulate data that should be confined to another origin, thereby compromising the confidentiality and integrity of web-site boundaries. The flaw is based on a weakness in how the Graphics component enforces site isolation, exposing inter‑origin data. The likely attack vector is a malicious webpage that triggers the Graphics component, but this is inferred from the nature of site isolation weaknesses.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird versions earlier than 153 are affected. The issue was mitigated in Firefox 153 and Thunderbird 153.
Risk and Exploitability
The CVSS score of 7.5 signifies a high severity impact, while the EPSS score of less than 1% indicates a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog and no public exploits are documented at present. Although exploitation would require interaction with the Graphics component, the low exploitation probability and absence of known attacks reduce the immediate urgency while still requiring remediation.
OpenCVE Enrichment