Impact
A side‑channel vulnerability exists in the Web Audio component of Mozilla Firefox and Thunderbird. This weakness could allow an attacker to obtain confidential information by observing timing or other side‑channel characteristics during audio processing. Based on the description, it is inferred that sensitive data such as encryption keys or audio content could be inferred, although the official advisories do not specify the exact data that may leak.
Affected Systems
The flaw affects all Mozilla Firefox releases prior to version 154 and Firefox ESR 153.1, as well as all Thunderbird releases prior to version 154 and Thunderbird ESR 153.1, regardless of platform.
Risk and Exploitability
At the time of analysis the EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 9.1 indicates critical severity. It is inferred that a malicious web page can exploit the vulnerability via the Web Audio API, potentially allowing side‑channel leakage of confidential information, though the limited EPSS suggests exploitation may not be common.
OpenCVE Enrichment