Impact
The vulnerability is a privilege escalation flaw within the WebExtensions component of Mozilla Firefox and Mozilla Thunderbird, allowing a WebExtension process to gain higher privileges than intended. The flaw is triggered when an extension misuses privileged APIs, resulting in a higher level of access than the extension was granted.
Affected Systems
Affected products are Mozilla Firefox and Mozilla Thunderbird. All releases of Firefox prior to version 156 and the ESR branches before ESR 115.41, 140.16, and 153.3 are vulnerable. Thunderbird versions before 156 or 140.16 are also affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high level of risk, and the EPSS score is <1%, while the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that a malicious or compromised WebExtension needs to be installed or executed with user‑accepted privileges for exploitation. The CVE description does not detail the exact exploitation path, so the real‑world likelihood of exploitation remains uncertain.
OpenCVE Enrichment
Debian DLA
Debian DSA