Impact
Based on the updated CVE description, this vulnerability enables an attacker to bypass security mitigations within the networking component of Mozilla products. The flaw was resolved in Firefox 153 and Thunderbird 153.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird. Versions earlier than 153 of either product are affected. The fix was introduced in release 153 of each product.
Risk and Exploitability
The maintenance team lists a CVSS score of 9.1 and an EPSS probability of less than 1 %. The vulnerability is not yet cataloged in CISA's KEV program. Based on the fact that the flaw resides in the networking layer, the likely attack vector would involve remote delivery of crafted network packets to the vulnerable software, although the official description does not specify this explicitly.
OpenCVE Enrichment