Impact
The vulnerability occurs in the Graphics: CanvasWebGL component and undermines site isolation, allowing one site to obtain information from another site’s WebGL rendering context. If an attacker can trigger the flaw, they could read or tamper with data that is supposed to be confined to a specific origin, thereby compromising confidentiality and potentially integrity of user data and application state. The issue directly impacts the browser’s ability to enforce the same-origin policy for graphics rendering and memory separation.
Affected Systems
Mozilla Firefox is affected by this site isolation flaw. The fix has been incorporated in Firefox version 154 and in the ESR branches 115.39, 140.14, and 153.1. Users running any earlier major release are susceptible and should upgrade to at least the listed versions to mitigate the risk.
Risk and Exploitability
The exploit path is grounded in WebGL execution within a malformed or malicious web page; exploit code would need to load a crafted script that interacts with the CanvasWebGL context. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so the probability of exploitation is currently unknown. Nonetheless, the lack of proper site isolation effectively lowers the barrier to cross‑site information disclosure, making the flaw a high‑impact concern for browsers that rely on WebGL for graphics. The severity, as implied by the description, is significant, but the exact CVSS score and exploitation likelihood cannot be determined from the provided data.
OpenCVE Enrichment