Impact
This flaw allows an attacker to gain higher privileges within the Firefox browser and Thunderbird by exploiting a weakness in the DOM navigation component. The vulnerability is an access-control failure that could enable the execution of privileged browser actions. No additional details are published regarding the extent of the damage, but the impact is a privilege escalation within the browser context.
Affected Systems
Affected releases include Mozilla Firefox154, Firefox ESR115.39, ESR140.14, ESR153.1, and Thunderbird154, Thunderbird140.14, and Thunderbird153.1; all earlier versions lacking the fix remain vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The flaw was highlighted in multiple Mozilla security advisories, indicating that it was considered serious. Based on the description, it is inferred that exploitation would require malicious web content that interacts with the DOM navigation component; however, no publicly available exploit or detailed exploitation path has been disclosed. Until a public exploit emerges, the risk remains theoretical but should be mitigated by patching.
OpenCVE Enrichment
Debian DLA
Debian DSA