Impact
The CVE description states that the WebAuthn component in Firefox for Android and Thunderbird allows spoofing of credentials, permitting an attacker to impersonate legitimate users. This undermines authentication processes and can lead to unauthorized access to accounts and services.
Affected Systems
Affected products include Mozilla Firefox for Android and Mozilla Thunderbird, any version prior to 148. Both browsers incorporate the vulnerable WebAuthn implementation.
Risk and Exploitability
The CVSS score of 9.8 signals a critical severity. The EPSS score of less than 1% indicates a low probability of exploitation today. The vulnerability is not listed in the CISA KEV catalog. The CVE does not specify the precise attack vector; any discussion of how an attacker might exploit the flaw is an inference rather than a statement from the CVE data.
OpenCVE Enrichment