Impact
The vulnerability allows a malicious page or script to alter the display of the web address in the browser’s address bar, a form of user‑interface spoofing identified as CWE‑451. The attacker could make a user believe they are visiting a trusted domain when they are actually interacting with a malicious site, potentially facilitating phishing or credential theft. The impact is limited to the user interface and does not directly grant code execution or privilege escalation, but it can lead to social engineering attacks.
Affected Systems
Mozilla’s Firefox and Thunderbird clients are affected; the flaw was fixed in Firefox 153 and Thunderbird 153, meaning all earlier releases are vulnerable. No specific sub‑versions beyond the 153 cutoff are listed.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not referenced in the CISA KEV catalog. Because the flaw requires an attacker to load a crafted web page or script that manipulates the address bar, it is presumed to be a local or network‑based attack, dependent on the user accessing malicious content. The risk is therefore mainly to end users who may be misled, rather than to the attacker’s control over the system.
OpenCVE Enrichment