Impact
The vulnerability is a site isolation issue that affects the Audio/Video: Web Codecs component. Site isolation is used by browsers to keep data and resources from one web origin separate from those of another. The CVE notes the issue but does not describe the specific data that could be accessed or how the isolation is broken, so the exact scope of the impact cannot be determined from the available information.
Affected Systems
Mozilla Firefox, including the Extended Support Release, and Mozilla Thunderbird, including the Extended Support Release, are affected. The bug was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird ESR 153.1, meaning any earlier releases are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score of < 1 % suggests that exploits are unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Because the CVE does not detail an exploit path, the most likely attack vector is inferred to be a malicious website that a user visits or a compromised extension that can trigger the Web Codecs API. This inference is based on typical site isolation weaknesses rather than explicit evidence in the description.
OpenCVE Enrichment