Impact
A flaw in Mozilla’s Push Subscriptions component allows an attacker to read data from the browser’s Document Object Model. The exposed information is sensitive data that should remain private to the application, making the vulnerability a confidentiality compromise. This weakness is classified as CWE-200 and CWE-201, both reflecting information disclosure, and the official description indicates the issue is limited to the DOM layer, not to server or network communications.
Affected Systems
Mozilla Firefox versions older than 154, as well as the ESR releases prior to 140.14 and 153.1, are impacted. The same set of versions applies to Mozilla Thunderbird: Thunderbird versions older than 154, as well as the ESR releases prior to 140.14 and 153.1. The vendor has fixed the issue in the corresponding newer releases.
Risk and Exploitability
The CVSS score of 4.3 reflects a low to moderate severity, and the EPSS score of 0.00261 indicates a very low exploitation probability, while the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Based on the description, the likely attack vector is a malicious web page that interacts with the Push API or otherwise manipulates the DOM to access the exposed data. The confidentiality impact is present, but overall risk remains moderate for typical users exposed to untrusted content.
OpenCVE Enrichment
Debian DLA
Debian DSA