Impact
The WebDriver BiDi component in Mozilla Firefox contains a flaw that can be leveraged to gain higher privileges than initially granted. This vulnerability allows an attacker to elevate privileges within the Firefox process, potentially enabling the execution of arbitrary code or privileged actions that were previously restricted. The weakness arises from improper authorization checks when handling browser bidirectional communication requests.
Affected Systems
Mozilla Firefox is affected. The flaw has been addressed in Firefox version 155, meaning all releases prior to 155 are vulnerable when the WebDriver BiDi feature is enabled.
Risk and Exploitability
Because the CVSS score is not publishered, the exact severity cannot be quantified, but privilege escalation is inherently high risk. The EPSS score is not available, indicating no data on current exploit activity, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploitation yet. Nevertheless, an attacker who can control or inject code into the WebDriver BiDi interface can achieve system‑level compromise. The likely attack vector is local or via a malicious web page that interacts with the browser’s WebDriver interface.
OpenCVE Enrichment