Impact
The vulnerability stems from a race condition in the XPConnect component, which allows privileged components to escape the browser sandbox. If an attacker is able to manipulate execution timing in the XPConnect interface, they can gain higher privileges than intended. The primary impact is circumvention of sandbox boundaries, providing a path to execute arbitrary code with the privileges of the application.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are impacted. All versions prior to 156 are vulnerable; version 156 onward contains the fix.
Risk and Exploitability
No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score is high (not provided explicitly). The race condition can be triggered through crafted content or scripts loaded by the user, making the attack vector likely from a compromised or malicious web page. Because the condition relies on timing, it may require precise conditions, but once achieved, the sandbox escape can compromise user data and system integrity.
OpenCVE Enrichment