Impact
This vulnerability allows an attacker to elevate privileges within the Firefox Downloads API component. By exploiting the flaw, an attacker could execute actions normally restricted to a more privileged user, potentially compromising the integrity of the browser and the data accessed through the download mechanism.
Affected Systems
Mozilla Firefox is affected. Versions prior to 154 and Firefox ESR versions prior to 153.1 contain the vulnerability.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the exploitation probability is not quantified. However, privilege escalation flaws are generally considered high-risk because they allow attackers to gain elevated capabilities. The likely attack vector is via malicious web content that interacts with the Downloads API, as the description does not specify an alternative path. Based on the nature of the flaw, the potential for local or browser-level code execution is plausible.
OpenCVE Enrichment