Impact
Site isolation in the Graphics: CanvasWebGL component allows a malicious webpage to access or manipulate a WebGL rendering context belonging to a different origin. The flaw sidesteps the browser’s same‑origin policy for graphics processing, enabling attackers to read sensitive data, perform cross‑site tracing, or alter the appearance or state of unrelated web applications. The impact is a compromise of confidentiality and integrity for any content rendered in WebGL.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are impacted. Versions before Firefox 154 and all ESR branches older than 115.39, 140.14, and 153.1, and Thunderbird versions older than 154 and ESR branches older than 140.14 and 153.1, are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 ranks this as medium‑to‑high severity. The EPSS score is below 1 %, indicating a low but nonzero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Exploitation requires a malicious webpage that can execute WebGL code, likely via social engineering or drive‑by download. In affected browsers with WebGL enabled, this can be achieved by a single page visit, making the attack path straightforward once the user loads a malicious site.
OpenCVE Enrichment
Debian DLA
Debian DSA