Impact
The vulnerability is a site isolation issue within the graphics subsystem of Mozilla products. It involves the lack of proper isolation between browsing contexts during graphics processing. Where a site can trigger the graphics code, the absence of isolation could allow that site to access or modify data that would normally be protected. This type of weakness could lead to leakage or unauthorized modification of sensitive information stored in other sites or contexts, though the exact extent depends on how data is handled by the graphics component. The weakness is identified as CWE‑346 and CWE‑653. The CVSS score of 9.1 indicates a critical potential impact.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird releases older than version 156 are affected. Any user running a version earlier than 156 on either product is vulnerable until the fix is applied in 156 or later.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low calculated probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. The issue is a site isolation bypass that could be exploited remotely through a malicious web page triggering vulnerable graphics operations. The exact likelihood is low based on the EPSS figure, and it is inferred from the description that an exploitation path might exist, but no concrete exploitation proof is reported at this time. The CVSS score of 9.1 reflects a critical potential impact. The issue falls under CWE‑346 and CWE‑653.
OpenCVE Enrichment