Impact
This vulnerability, titled "Other issue in the DOM: Navigation component", was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. The description indicates an issue in the navigation component’s input handling, which is classified as CWEs 200 and 79. While no explicit exploitation vector is documented, the flaw appears to affect browser navigation behavior, potentially allowing a malicious site to influence the browser’s navigation path and redirect users to unintended or harmful destinations without granting code execution privileges.
Affected Systems
Mozilla Firefox versions before 155 and the Firefox ESR branch below 153.2, along with Mozilla Thunderbird versions before 155 and the Thunderbird ESR branch below 153.2, are affected. All later releases are considered secure as the flaw has been resolved.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low exploit probability, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 9.8, classifying it as critical severity. While no explicit exploitation vector is documented, it is inferred that a malicious web page could exploit the DOM navigation component, leading to navigation manipulation without code execution privileges. The overall risk is limited to browser navigation disruption.
OpenCVE Enrichment