Impact
A flaw in Mozilla’s Firefox and Thunderbird? DOM navigation component improperly enforces site isolation, allowing maliciously crafted content to break isolation boundaries between distinct browsing contexts. This weakness, classified as CWE‑346 Authentication Bypass, can enable an attacker to read data that should remain confined to another site or application, potentially leading to disclosure of sensitive information.
Affected Systems
Mozilla’s Firefox and Thunderbird products are vulnerable in any release older than version 153; users who have not updated to Firefox 153 or Thunderbird 153 remain exposed to the site isolation flaw.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The likely attack vector is remote, via crafted web content or a compromised site, although the description does not detail an explicit exploitation path.
OpenCVE Enrichment