Impact
The bug permits a web page to bypass the browser’s same-origin policy within the Networking: Cookies component. The flaw can potentially allow an attacker to interact with cookies that belong to different origins, which could expose session tokens or other sensitive information. The vulnerability was addressed in Firefox 154, ESR 140.14, ESR 153.1, and Thunderbird 154, 140.14, 153.1.
Affected Systems
Mozilla Firefox versions up to and including 154, ESR 140.14, and ESR 153.1 are affected. Thunderbird releases up to and including 154, 140.14, and 153.1 are also vulnerable. The issue was fixed in the specified versions and subsequent releases.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly reported exploits at the time of analysis. A bypass of the same-origin policy in the Cookies component could potentially allow attackers to leverage cross-origin cookie access, posing a risk to authentication and session integrity. The risk is heightened for users who interact with unsanctioned web content or rely on browser extensions that inject or modify page content. While no active exploits are known, the theoretical impact on confidentiality and integrity warrants remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA