Impact
This vulnerability allows an attacker to elevate privileges within the Downloads API component of Firefox and Thunderbird. The flaw was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird ESR 153.1.
Affected Systems
Mozilla Firefox and Thunderbird are affected. Versions prior to 154 and Firefox ESR versions prior to 153.1, and Thunderbird versions prior to 154 and Thunderbird ESR versions prior to 153.1 contain the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1% suggests a very low exploitation probability and the vulnerability is not listed in the CISA KEV catalog. However, privilege escalation flaws are generally considered high‑risk because they allow attackers to gain elevated capabilities. The likely attack vector is via malicious web content that interacts with the Downloads API, as the description does not specify an alternative path. Based on the nature of the flaw, the potential for local or browser‑level code execution is plausible.
OpenCVE Enrichment