Impact
This vulnerability originates in the DOM networking component of Mozilla’s browsers and the Thunderbird mail client. It allows an attacker to craft content that fools the component into treating a network request as if it came from a trusted origin, effectively bypassing the browser‑level restrictions that normally block such traffic. Because the flaw deals with improperly enforced network‑related safeguards, it can lead to delivery of malicious payloads or data that should normally be blocked, although the CVE text does not state the exact downstream consequences. The impact focuses on the loss of the protection that the network component is supposed to enforce.
Affected Systems
Firefox versions before 156 and Firefox ESR releases older than 153.3, and Thunderbird builds earlier than 156 or ESR 153.3 remain vulnerable until upgraded to the specified fixed releases.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, while the EPSS score of <1% shows a very low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector involves a malicious web page or email message that contains crafted DOM operations. Attackers would need the victim to view or open the engineered content, after which the browser or client might process otherwise disallowed network requests, potentially enabling further malicious activity. The risk is therefore high if the user visits untrusted content, but exploitation likelihood remains low.
OpenCVE Enrichment