Impact
The most recent security advisory clarifies that the Remote Settings Client component contains a sandbox escape flaw (CWE-653, CWE-693). The description does not specify how the flaw is triggered, but it is inferred that malicious remote settings data processed by the component could allow an attacker to break out of the browser’s process sandbox and execute code with the client’s privileges. If successfully exploited, this would compromise confidentiality, integrity, and availability of the victim’s machine, representing a remote code execution path.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird users running versions earlier than 154 are vulnerable. The Remote Settings Client is part of the core components delivered by Mozilla, affecting all installations of Firefox and Thunderbird that have not yet been updated to the patched build.
Risk and Exploitability
The CVSS score is 10, indicating a critical level of severity. The EPSS score of < 1% indicates a very low exploitation probability. This vulnerability is not listed in CISA’s KEV catalog, which means there is no confirmed widespread exploitation yet, but the potential for serious impact remains. Based on the description, it is inferred that the likely attack vector is through remotely delivered settings or configuration data, which can be controlled by a malicious web server or compromised network infrastructure. The CVE description does not specify whether authentication or local access is required to trigger the flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA