Impact
The vulnerability allows a web page to bypass the browser’s notification permission mechanism, causing desktop notifications to appear as if the user had explicitly granted permission. The flaw is limited to the notification component and does not provide a pathway for arbitrary code execution or direct access to protected data. The description does not indicate exploitation beyond the premature notification display.
Affected Systems
Mozilla Firefox versions older than 156 and the Firefox ESR 153.3 branch, as well as Mozilla Thunderbird releases older than 156 and the Thunderbird ESR 153.3 release, are impacted. The bug was corrected in Firefox 156/ESR 153.3 and Thunderbird 156/ESR 153.3.
Risk and Exploitability
With a CVSS base score of 6.3 this issue is considered medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The likely attack vector is a remote web page that invokes the Notification API, and based on the description it is inferred that this could trigger the flaw. The vulnerability is not listed in the CISA KEV catalog, suggesting no large-scale public exploit has been reported.
OpenCVE Enrichment