Impact
The vulnerability weakens the enforcement of site isolation within Firefox’s and Thunderbird’s WebExtensions component. Site isolation is designed to keep different web origins in separate browsing contexts. A failure here could allow a malicious extension or a compromised webpage to bypass those boundaries and access data that should be isolated. Because the description does not detail the exact exploitation method or outcome, this potential compromise is inferred from the nature of site isolation.
Affected Systems
Mozilla Firefox versions older than 154 and earlier Extended Support Release versions before 140.14 and 153.1 are affected, as are Mozilla Thunderbird releases older than 154 and ESR releases before 140.14 and 153.1. Upgrading to at least Firefox 154, ESR 140.14 or ESR 153.1, or Thunderbird 154, ESR 140.14 or ESR 153.1 removes the weakness.
Risk and Exploitability
The CVSS score of 8.1 expresses high severity. EPSS indicates a very low exploitation probability of less than 1 per cent. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector would involve a malicious or compromised WebExtension or webpage attempting to override site isolation boundaries, though no public exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA