Impact
This vulnerability in the DOM Push Subscriptions component of Mozilla Firefox breaks site isolation boundaries, allowing a malicious webpage to access push subscription data that normally belongs to a different origin. The flaw could lead to the disclosure of subscription identifiers and potentially other user data, compromising confidentiality.
Affected Systems
The issue affects Mozilla Firefox versions earlier than 155 and the ESR 153.2 branch. Users should upgrade to Firefox 155 or any newer ESR release that includes the fix.
Risk and Exploitability
No CVSS score is provided and the EPSS score is not reported. The vulnerability is also not listed in the CISA KEV catalog. The flaw affects a widely deployed feature and can be triggered via a malicious website. Although the lack of reporting does not imply low risk, it remains a high-impact confidentiality issue that can be exploited remotely by presenting crafted web content to the victim's browser.
OpenCVE Enrichment