Impact
The vulnerability is a side‑channel information disclosure in the Storage: Cache API component of Mozilla Firefox and Thunderbird. It allows unintended access to data stored in the browser cache, thereby compromising confidentiality. The flaw was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected Systems
The issue affects versions of Mozilla Firefox that were released prior to the bug fix, specifically browsers updated before Firefox 154 and before Firefox ESR 153.1. Any installation of those earlier releases that includes the Storage: Cache API component is susceptible. The problem is not present in Firefox 154 and later, nor in ESR 153.1 and newer. The same vulnerability also impacts Thunderbird releases older than Thunderbird 154 and Thunderbird ESR 153.1.
Risk and Exploitability
The EPSS score is 0.00256 (~0.256%), and the vulnerability is not listed in CISA's KEV catalog, indicating no confirmed exploit activity to date. The CVSS score of 7.5 reflects a high severity level. Nonetheless, because the flaw relies on a side‑channel in browser storage that can be triggered by crafted web content, the attack vector is likely local within the user’s browser session. An attacker who can deliver malicious scripts to a user’s browser—such as through a compromised website or phishing—could exploit the vulnerability without needing elevated privileges, leading to potential confidentiality loss. The risk is elevated in environments where users access sensitive information through the Storage: Cache API.
OpenCVE Enrichment