Impact
The Storage: Cache API component contains a flaw that allows an attacker to bypass internal browser security controls. This oversight undermines the intended isolation of the Cache API, meaning a malicious script could read or manipulate cached data that should otherwise be protected. The weakness is classified both as a missing authentication for a system function (CWE‑807) and as a lack of security awareness for a component (CWE‑693). The CVSS score of 9.1 indicates high severity, reflecting the potential for data compromise if exploited.
Affected Systems
Mozilla Firefox builds prior to version 154, and the ESR releases 140.14 and 153.1, as well as Mozilla Thunderbird builds earlier than version 154, and the ESR releases 140.14 and 153.1 are vulnerable. Users of these builds should consider themselves at risk until the security update is applied.
Risk and Exploitability
The EPSS score is below 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The component is exposed to web content, so the most likely attack vector is via a malicious or compromised web page. No public exploits have been reported, but the bypass of core mitigations could have significant consequences if an attacker succeeds. While exploitation likelihood is low, the potential impact justifies prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA