Impact
The vulnerability enables a malicious webpage to bypass the browser’s same‑origin policy by manipulating the DOM’s networking component. While the description does not detail the exact data that can be accessed, it is inferred that an attacker could potentially read data from other origins, such as cookies, LocalStorage, or session information, leading to confidential data exposure. This vulnerability involves CWE-942.
Affected Systems
Mozilla Firefox and Thunderbird browsers released before version 151 are affected. The issue is present on all operating systems that support either browser until the user upgrades to the fixed release or later.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no known public exploitation at the time of analysis. The CVSS score is 9.1, indicating a critical severity. The attack likely requires a user to visit a malicious or compromised website capable of crafting the DOM manipulation. The lack of exploitation data suggests the likelihood of widespread exploitation is uncertain, but the potential impact on confidentiality is significant if the SOP bypass is successfully achieved.
OpenCVE Enrichment