Impact
Attacker can bypass the browser's Data Loss Prevention (DLP) feature, which is designed to intercept and block content that could lead to data leakage. This bypass occurs due to a flaw in the DLP enforcement engine. The effect is that normally restricted or sensitive data may be transmitted or processed without restriction, exposing the user to accidental or malicious data exfiltration. This weakness corresponds to insufficient security checks (CWE-693) and input validation (CWE-807).
Affected Systems
Affect Mozilla Firefox and Mozilla Thunderbird product lines. One or more releases of both browsers are affected. The issue has been fixed in Firefox 154 and in the ESR tracks 140.14 and 153.1, and in Thunderbird 154 and in the ESR tracks 140.14 and 153.1. All versions prior to these releases that are still running need to be evaluated and upgraded. The designation applies broadly to desktop builds using the Data Loss Prevention feature.
Risk and Exploitability
The CVSS score is 8.1, and the EPSS score is <1%. The vulnerability remains a high‑impact issue because the Data Loss Prevention bypass can lead to data leakage. Based on the description, it is inferred that an attacker would need to deliver crafted content to the browser to trigger the DLP engine, as the bypass occurs within the enforcement component. Since the vulnerability is published and not listed in the KEV catalog, proactive monitoring and prompt patching are recommended to mitigate potential exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA