Impact
A vulnerability was discovered that allows the navigation component of the browser’s Document Object Model to bypass site isolation. An attacker could place malicious content in one browsing context that reads or manipulates the DOM of a different origin. This breach can expose confidential data or allow unauthorized changes to a page. The weakness is an access‑control issue reflecting improper isolation of browsing contexts.
Affected Systems
Mozilla Firefox is affected. Any release prior to Firefox 155 and Firefox ESR 153.2 is vulnerable; these older versions fail to enforce complete DOM isolation between sites.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker who can lure a user to a malicious site might read or manipulate another site's DOM, possibly leaking data. The cross‑origin nature of the attack raises the potential impact, but the lack of available exploitation tools reduces immediate threat.
OpenCVE Enrichment