Impact
This vulnerability is a failure of site isolation in the CSS Parsing and Computation component, allowing resources from separate browsing contexts to be accessed unintentionally. The weakness is reflected by CWE-200 and CWE-501, indicating that confidential data could leak and that content may be mishandled in ways that undermine isolation assumptions. The impact is a breach of data confidentiality across contexts that should remain separate, potentially exposing sensitive information to unintended parties.
Affected Systems
Mozilla Firefox versions earlier than 154 and ESR 153.1, as well as Mozilla Thunderbird versions earlier than 154 and ESR 153.1, are vulnerable until they are updated to the fixed releases.
Risk and Exploitability
The EPSS score is reported as < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that current exploitation activity is limited. With a CVSS score of 9.1, the severity is critical. Based on the description, it is inferred that the likely attack vector is a malicious website delivering specially crafted CSS that a browser engine parses and applies, potentially allowing data from isolated contexts to be accessed or manipulated. The high severity warrants prompt mitigation even though widespread exploitation is not yet evidenced.
OpenCVE Enrichment