Description
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Published: 2026-05-19
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability enables a malicious webpage to bypass the browser’s same‑origin policy by manipulating the DOM’s networking component. While the description does not detail the exact data that can be accessed, it is inferred that an attacker could potentially read data from other origins, such as cookies, LocalStorage, or session information, leading to confidential data exposure. This vulnerability involves CWE-942.

Affected Systems

Mozilla Firefox and Thunderbird browsers released before version 151 are affected. The issue is present on all operating systems that support either browser until the user upgrades to the fixed release or later.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no known public exploitation at the time of analysis. The CVSS score is 9.1, indicating a critical severity. The attack likely requires a user to visit a malicious or compromised website capable of crafting the DOM manipulation. The lack of exploitation data suggests the likelihood of widespread exploitation is uncertain, but the potential impact on confidentiality is significant if the SOP bypass is successfully achieved.

Generated by OpenCVE AI on May 19, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Firefox installations to version 151 or later
  • Upgrade all Thunderbird installations to version 151 or later
  • Remove or disable any older Firefox versions from the environment to prevent inadvertent use
  • Remove or disable any older Thunderbird versions from the environment to prevent inadvertent use
  • Configure automated update policies and monitor web content for SOP‑bypass exploits

Generated by OpenCVE AI on May 19, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 20 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 19 May 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 19 May 2026 17:45:00 +0000

Type Values Removed Values Added
Description Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151. Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
References

Tue, 19 May 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-942
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 19 May 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 19 May 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 19 May 2026 13:45:00 +0000

Type Values Removed Values Added
Description Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151.
Title Same-origin policy bypass in the DOM: Networking component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-19T17:10:52.773Z

Reserved: 2026-05-19T12:29:38.570Z

Link: CVE-2026-8948

cve-icon Vulnrichment

Updated: 2026-05-19T16:41:04.209Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-19T14:16:51.027

Modified: 2026-05-20T14:53:13.603

Link: CVE-2026-8948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-19T20:30:13Z

Weaknesses
  • CWE-942

    Permissive Cross-domain Security Policy with Untrusted Domains