Impact
The vulnerability is a flaw in the graphics component that undermines site isolation, potentially allowing a malicious web document to read or infer data from another site within the same rendering context, facilitating information disclosure. The weakness is reflected in CWE‑346 (Untrusted Data as a Decision Element) and CWE‑501 (Information Exposure through Environmental Information).
Affected Systems
Mozilla Firefox versions prior to 154 on the standard channel, Firefox ESR releases prior to 153.1, and all Thunderbird releases prior to 154 are affected; the fix is included in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk. EPSS less than 1% denotes a very low predicted exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector would require a user to visit a malicious web page that exploits the graphics component; no additional network or privilege escalation is required beyond normal browser use.
OpenCVE Enrichment