Impact
The vulnerability resides in the networking component of the DOM and is a CWE-284: Improper Access Control flaw that enables an attacker to elevate privileges, potentially allowing execution of privileged network operations or reading of sensitive data normally inaccessible to standard web content. Because it involves improper authorization controls within the DOM, exploitation could compromise confidentiality, integrity, or both, depending on the attacker’s objectives.
Affected Systems
Mozilla Firefox is affected. Versions earlier than Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1 contain the flaw and must be updated.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog, but its nature—privilege escalation—suggests a high impact if exploited. The most likely attack vector is via malicious web content that manipulates the DOM, implying the risk is highest on systems where untrusted web pages are accessed without restrictions.
OpenCVE Enrichment