Impact
The vulnerability allows a malicious web origin to bypass the same‑origin policy in the DOM Service Workers component, giving the attacker the ability to interact with, read data from, or register Service Workers that belong to other origins. The flaw also includes a type conversion problem classified as CWE‑843, which can lead to improper handling of input types and potentially further compromise. The combination of these weaknesses can result in confidentiality and integrity violations in an affected browser.
Affected Systems
Versions of Mozilla Firefox and Thunderbird older than major revision 154, including the ESR branches prior to ESR 153.1, are vulnerable. The issue was fixed starting with Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird ESR 153.1.
Risk and Exploitability
The CVSS score of 9.1 indicates a severe impact on confidentiality and integrity. With an EPSS score of < 1 % and no listing in the CISA KEV catalog, current exploitation activity is expected to be rare, but the vulnerability remains highly exploitable via a malicious web origin that can register or manipulate Service Workers. Based on the description, the likely attack vector is a remote web page that coerces the vulnerable browser into executing the Service Worker API with cross‑origin input.
OpenCVE Enrichment