Impact
A vulnerability was found in browsers that do not properly isolate the Document Object Model (DOM) for navigation. The navigation component can be abused to read or modify the DOM of a different origin, enabling an attacker to obtain confidential data or alter the content of other sites. The flaw is an access‑control weakness that breaks cross‑origin isolation.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Any release prior to Firefox 155, Firefox ESR 153.2, Thunderbird 155, or Thunderbird ESR 153.2 is vulnerable; these older versions fail to enforce complete DOM isolation between sites.
Risk and Exploitability
With a CVSS score of 9.8, this vulnerability is considered critical. The EPSS score is less than 1%, indicating a low probability of exploitation, and it is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker who can lure a user to a malicious site might read or manipulate another site's DOM, possibly leaking data. The cross‑origin nature of the attack raises the potential impact, but the lack of available exploitation tools reduces immediate threat.
OpenCVE Enrichment