Impact
A flaw in Firefox’s site isolation for the DOM navigation component can allow a malicious web origin to access resources or data from other origins that should have been isolated. This vulnerability could enable an attacker to read or manipulate content belonging to another site.
Affected Systems
Mozilla Firefox versions earlier than 155 in the main line, and the ESR release before 153.2, contain the vulnerable navigation component.
Risk and Exploitability
The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog and no EPSS score is available. The likely attack vector involves a crafted navigation request or link that a victim interacts with, such as through a malicious web page or spear-phishing email. Based on the description, it is inferred that the attacker would need to deliver such a crafted navigation request to the victim’s browser. Exploitation would target the browser’s DOM navigation handling code, bypassing the isolation boundary and enabling the attacker to read or manipulate data from another site. Because it requires user interaction with malicious content, the likelihood is moderate, but the potential for data leakage makes it high priority for remediation.
OpenCVE Enrichment