Impact
This vulnerability involves a flaw in Firefox’s navigation component that can affect how the browser handles DOM changes. The defect may allow an attacker, via a crafted web page, to manipulate navigation behavior or redirect users to unintended sites.
Affected Systems
Mozilla Firefox versions prior to 155 and the Firefox ESR branch below 153.2 are vulnerable. The issue was fixed in Firefox 155 and Firefox ESR 153.2. All other versions are unaffected.
Risk and Exploitability
EPSS score unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating limited public exploitation data. There is no CVSS score provided, so the severity cannot be quantified here. The likely attack vector is a malicious web page that exploits the DOM navigation component; the exploit would require the victim to visit a crafted site, and the consequence is limited to manipulation of navigation behavior rather than full code execution.
OpenCVE Enrichment