Impact
The flaw is located in Mozilla Firefox’s Security component. It allows an attacker to read sensitive information that resides in the Document Object Model. The exposure could include URLs, user credentials, or other configuration details that normally remain confidential, resulting in an information‑exposure weakness. Based on the description, it is inferred that the attacker may trigger this issue via a malicious web page or script.
Affected Systems
All releases of Mozilla Firefox and Thunderbird prior to version 151 are affected. The issue was rectified in version 151, so any installation older than that release contains the vulnerability.
Risk and Exploitability
The CVSS score is 7.5 and the EPSS score is less than 1%, indicating a moderate to high severity but a low exploitation probability. The description indicates the vulnerability involves information disclosure in the DOM, but does not specify the attack vector. Based on the nature of the flaw, it is inferred that a web‑based attack might trigger the bug. The lack of a KEV listing and absence of widespread exploitation evidence suggest the risk is currently low, but the impact is significant if compromised.
OpenCVE Enrichment