Impact
The vulnerability resides in the storage subsystem of Mozilla's IndexedDB engine. The advisory indicates that the issue is fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird ESR 140.10. The CVE is tagged with CWE‑200 and CWE‑440, which point to potential information disclosure and improper boundary restrictions. Based on the absence of a more detailed failure mode, it is inferred that an attacker could read or otherwise misuse data stored in IndexedDB through inadequate validation of boundaries.
Affected Systems
Mozilla products Firefox and Thunderbird may be affected. The flaw exists in all builds older than Firefox 150 and Firefox ESR 140.10, as well as Thunderbird 150 and Thunderbird ESR 140.10. Users running any earlier version are potentially exposed to the vulnerability. The flaw is classified as CWE‑200 and CWE‑440.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the advisory and the CWE identifiers, it can be inferred that the attack would likely involve a local user or a web page executing in the same origin, with no stated requirement for privileged access or remote code execution. The only prerequisite disclosed is the presence of an affected version; it is inferred that no special setup beyond that is necessary.
OpenCVE Enrichment
Debian DLA
Debian DSA