Impact
The Add‑ons Manager component suffers from a mitigation bypass that allows an attacker to install extensions that would normally be disallowed. Based on the description, it is inferred that installing a malicious add‑on could allow arbitrary code execution within the browser context, potentially compromising user data and browsing integrity. The flaw is rooted in improper access control (CWE‑284) and missing verification of add‑on constraints (CWE‑807).
Affected Systems
All Mozilla Firefox releases prior to version 154 and the ESR 153.1 line before the patch, as well as all Mozilla Thunderbird releases prior to version 154 and the corresponding ESR 153.1 branch, remain vulnerable if the Add‑ons Manager component is available and not disabled.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a user interacting with the Add‑ons Manager or installing an add‑on from an offline source; based on the description, it is inferred that the attacker must persuade the user to run the malicious add‑on to bypass the restricted installation checks.
OpenCVE Enrichment