Impact
A mitigation bypass vulnerability was identified in the Service Workers component of Mozilla's DOM handling. The description states that the browser’s built‑in security checks can be overridden, allowing an attacker to bypass intended authorization controls. This flaw involves improper authorization (CWE‑284), insecure persistence mechanisms (CWE‑693), and potential data leakage (CWE‑807).
Affected Systems
The flaw impacts Mozilla Firefox and Mozilla Thunderbird. Versions prior to 153 are affected; upgrading to Firefox 153 or later, or Thunderbird 153 or later, eliminates the issue.
Risk and Exploitability
The CVSS score of 9.8 classifies the bug as critical, while the EPSS score of <1% indicates a low likelihood of exploitation at the time of assessment. The vulnerability is not listed in CISA KEV. Based on the description of a mitigation bypass, it is inferred that a malicious website could register a compromised Service Worker in a user’s browser, leading the worker to override security checks. No definitive attack steps are provided in the CVE text, so the exact exploitation path remains speculative.
OpenCVE Enrichment