Impact
The vulnerability is a site isolation flaw in the Graphics: WebRender component of Mozilla Firefox and Thunderbird. It permits an attacker to break the separation between distinct web pages, enabling cross‑origin data leakage. This is an Access Control weakness (CWE‑346) and also involves a lack of proper isolation controls (CWE‑501). While the official description does not detail how the data would be accessed, it is inferred that the attacker could read data from other origins after triggering the flaw. No direct code‑execution privileges are required.
Affected Systems
Mozilla Firefox versions earlier than 154 and the Firefox ESR 153.1 line, as well as Mozilla Thunderbird versions earlier than 154 and Thunderbird ESR 153.1, are affected. The issue was resolved in Firefox 154/ESR 153.1 and Thunderbird 154/ESR 153.1.
Risk and Exploitability
The CVSS score is 5.4, indicating moderate severity. The EPSS score is below 1% (~0.00113), signifying a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Based on the description, the attack vector would be a malicious web page that triggers the WebRender flaw, potentially allowing the attacker to read data from other sites. Although the potential impact is significant, the low exploitation probability reduces immediate risk, but it is prudent to apply the fix as soon as possible.
OpenCVE Enrichment