Impact
The vulnerability resides in a DOM security component that can expose sensitive information to an attacker. It is classified as a CWE‑200 data‑exposure weakness. An attacker may obtain data that should remain private, potentially compromising user confidentiality if the component processes untrusted input.
Affected Systems
Mozilla’s Firefox and Thunderbird applications are affected, specifically all releases prior to version 153. Users on any earlier Firefox or Thunderbird build are vulnerable and require upgrading.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high severity, while the EPSS score of less than 1 % suggests that actual exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through a malicious web page or malicious email that leverages the affected DOM security component. Successful exploitation would allow an attacker to read data that should be protected, but would not provide complete system compromise.
OpenCVE Enrichment