Impact
A flaw in the Audio/Video: Playback component permits browsers to break same-origin restrictions on media playback, allowing an attacker to access or alter data that should be confined to another origin. The vulnerability is rooted in improper handling of media URLs and satisfies the weaknesses listed in CWE-346 and CWE-940. The stated CVSS score of 5.4 indicates a moderate severity, reflecting that the impact is limited to unintended cross-origin data access rather than full system compromise.
Affected Systems
Mozilla Firefox builds before version 154, as well as the ESR releases 140.14 and 153.1, are affected. The same applies to Mozilla Thunderbird prior to version 154, and the ESR builds 140.14 and 153.1. Users running any of these releases are vulnerable until they transition to a newer build.
Risk and Exploitability
The likely attack vector is client‑side; it is inferred that a malicious web page or local media file could trigger the bypass when a victim renders media in a compliant browser. With an EPSS of less than 1% and no listing in the CISA KEV catalog, exploitation is considered unlikely, yet it is possible. The weakness allows attackers to read or manipulate cross‑origin data, potentially enabling secondary attacks such as phishing or data theft. Because the flaw resides in the core playback engine, no special privileges are required beyond the victim’s normal browsing activity.
OpenCVE Enrichment
Debian DLA
Debian DSA