Impact
Mitigation bypass in the Remote Settings Client component allows an attacker to override built‑in safeguards for configuration settings that are fetched from a remote server. If exploited, the client could accept and persist malicious or undesired settings, thereby altering its behavior or disabling security features before the user is aware. This vulnerability could enable persistence of unwanted configuration changes at the local level, compromising the integrity of the application.
Affected Systems
This issue affects Mozilla products Firefox and Thunderbird. Versions older than 156, and the ESR releases, and 153.3 for each product, are vulnerable. Any installation running those builds is impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require influence over the remote settings service or the ability to trigger a policy download, which is not a standard public exploitation path.
OpenCVE Enrichment
Debian DLA
Debian DSA