Impact
The vulnerability is a site isolation flaw in the Networking: Cookies component of Mozilla browsers. It is inferred that this flaw allows a web origin to read cookies from another origin, which could expose session identifiers or other sensitive data, potentially enabling session hijacking or unauthorized data exposure. The issue affects any version of Firefox or Thunderbird older than the patched releases (Firefox 154, ESR 140.14, ESR 153.1, Thunderbird 154, Thunderbird 140.14, Thunderbird 153.1). The likelihood of exploitation relies on a malicious web page or script that can trigger the unsafe cookie access. The attack vector and impact details are inferred from the description. This weakness is classified as CWE-1100 and CWE-346.
Affected Systems
Mozilla Firefox users operating on any version preceding Firefox 154, Firefox ESR 140.14, or Firefox ESR 153.1 are affected. Mozilla Thunderbird users on any version preceding Thunderbird 154, Thunderbird 140.14, or Thunderbird 153.1 are also affected. This includes all mainstream releases up to Firefox 153 and all ESR streams older than the specified patch versions.
Risk and Exploitability
Exploitation would likely involve a malicious web page or script that can read cookies from another site context, exposing session identifiers and sensitive data. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 8.1 indicates a high severity level. The attack vector is inferred to be a malicious web page that triggers unsafe cookie access, relying on the missing isolation guarantees of the Networking: Cookies component.
OpenCVE Enrichment
Debian DLA
Debian DSA