Impact
This vulnerability permits a sandbox escape in the DOM Core and HTML components of Mozilla browsers and email client. An attacker who can supply or influence HTML or DOM content—such as a malicious web page or compromised email attachment—can potentially bypass the sandbox restrictions that normally isolate such content from the rest of the system, leading to execution of arbitrary code or the compromise of data integrity and confidentiality.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Versions prior to Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3 are vulnerable. Upgrading to the stated release numbers removes the flaw.
Risk and Exploitability
The EPSS score of 0.0016 (less than 1%) indicates a very low currently observed exploitation probability, but the CVSS score of 9.6 and the nature of a sandbox escape remain sufficient to warrant concern. The likely attack vector is a malicious web page or email attachment that delivers crafted DOM content, which an attacker can use to escape the browser or email client sandbox and potentially execute code or access sensitive information. This vulnerability is not listed in CISA KEV, indicating no known widespread exploitation at the time of reporting.
OpenCVE Enrichment
Debian DLA
Debian DSA