Impact
This flaw allows a malicious or compromised web site to register a Service Worker that can operate with unexpectedly elevated privileges inside the Document Object Model. By manipulating how the Service Workers component handles certain requests, an attacker can gain higher authority than their original context provides, potentially executing operations or accessing data beyond the scope of the website’s normal permissions. The impact is a Privilege Escalation that can compromise the integrity of the affected application for the user or organization.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are impacted. The vulnerability is fixed in Firefox 156 and the ESR releases 115.41, 140.16, and 153.3, as well as in Thunderbird 156 and the ESR releases 140.16 and 153.3. Any earlier versions of these browsers remain vulnerable.
Risk and Exploitability
The high CVSS score of 8.8 reflects the severity of the privilege escalation once the flaw is triggered. The EPSS score of less than 1% indicates that, at the time of analysis, exploitation in the wild is considered unlikely, and the role in CISA's KEV catalog is not present. The most probable attack vector involves a malicious or compromised site that leverages Service Workers to elevate operations; explicit prerequisites are not detailed in the provided data, so the attack is inferred rather than explicitly documented.
OpenCVE Enrichment
Debian DLA
Debian DSA