Impact
The vulnerability allows a local attacker to elevate privileges within the application through the Developer Tools component. The bug is classified as CWE-269, and could enable the attacker to bypass normal permission constraints and gain higher level access than intended.
Affected Systems
All users running Mozilla Firefox versions before 156 or before ESR 153.3, and users of Thunderbird versions before 156 are affected. Updating to the patched releases eliminates the flaw.
Risk and Exploitability
With a CVSS score of 8.8 this issue is considered high severity. No EPSS score is available, but the lack of an exploit listing in the CISA KEV catalog does not reduce its potential impact. The likely attack vector is a local user or code that can access the DevTools interface; based on the description, it is inferred that an attacker can exploit the bug while the affected application is running.
OpenCVE Enrichment