Impact
The flaw resides in the Networking: Cookies component of Mozilla Firefox and Thunderbird, allowing an attacker who can reach the vulnerable cookie handling logic to elevate privileges on the target system. This could enable unauthorized code execution or access to sensitive data. The issue is identified as improper authorization (CWE-269) and improper handling of elevated privileges (CWE-472).
Affected Systems
Mozilla Firefox versions earlier than 154, as well as Firefox ESR 140.14 and 153.1, and Mozilla Thunderbird versions earlier than 154, including Thunderbird ESR 140.14 and 153.1, are affected. The fix is available in Firefox 154, ESR 140.14, and 153.1, and Thunderbird 154, ESR 140.14, and 153.1.
Risk and Exploitability
The CVSS score of 8.8 reflects a high‑severity privilege-escalation flaw. EPSS data indicates a very low exploitation probability (<1%). The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. The likely attack vector involves local interaction with the cookie handling logic or a remotely crafted network packet that triggers the flaw, leading to privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA