Impact
The flaw exists in the networking component of the Document Object Model and is a privilege escalation vulnerability (CWE-266 and CWE-269). An attacker could gain elevated privileges within the browser process, enabling unauthorized network operations or access to data normally restricted to standard web content. This can compromise confidentiality, integrity, or both, depending on the attacker’s objectives. The vulnerability was fixed in Firefox 154, Firefox ESR 115.39, 140.14, and 153.1, as well as Thunderbird 154, 140.14, and 153.1.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. All versions prior to Firefox 154, Firefox ESR 115.39, 140.14, and 153.1, and prior to Thunderbird 154, 140.14, and 153.1 contain the flaw and require updating.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. Because the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the exploitation probability is unknown but potentially significant. The most likely attack vector is malicious web content that manipulates the DOM, which can affect any user opening untrusted pages in the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA