Impact
The vulnerability resides in Mozilla’s DOM UI Events & Focus Handling code and permits a malicious web page to read internal browser UI state, thereby leaking sensitive information to the attacker. The description does not enumerate the exact data that can be disclosed, but the stated impact is information disclosure within the DOM. The weakness is a classic confidentiality issue (CWE‑200) where data that should be shielded is exposed to an unauthorized party. The vulnerability also maps to CWE‑360.
Affected Systems
Mozilla Firefox and Thunderbird releases prior to version 154, as well as the ESR builds 140.14 and 153.1, contain the unpatched code and are therefore affected. Versions 154 and later, plus ESR 140.14+, 153.1+, include the fix that removes the vulnerability.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is 0.00261, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation activity. Based on the description, the flaw is likely exploitable from a remote context—an attacker can host a crafted web page that triggers the vulnerable UI events and reads the leaked data. The overall risk to confidentiality is moderate, with exploitation feasibility inferred from the remote attack vector but not confirmed by available exploitation metrics.
OpenCVE Enrichment
Debian DLA
Debian DSA