Impact
This vulnerability allows an attacker who can influence the Enterprise Policies component in Mozilla Firefox or Thunderbird to bypass security mitigations that are normally enforced by those policies. The flaw resides in an inadequate check of policy enforcement logic, enabling the attacker to execute actions that would normally be restricted. The impact includes unauthorized configuration changes, potential elevation of privileges, and the ability to tamper with application settings that could compromise data confidentiality and integrity. It aligns with weaknesses such as improper authorization (CWE-285) and improper check of permissions (CWE-640).
Affected Systems
Mozilla Firefox and Thunderbird, versions prior to the fix in Firefox 156, Firefox ESR 153.3, and Thunderbird 156, are affected. The vulnerability is present in the Enterprise Policies component of both browsers.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable, so the exact technical severity cannot be determined from the public data. However, because the flaw permits a bypass of enterprise policy controls, it is likely to be considered high risk for organizations that rely on those policies for security. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating that there are no confirmed active exploits at the time of this report. The attacker would need to gain local user access or otherwise influence the policy engine; the attack vector appears to require interaction with the affected application rather than a network‑based intrusion, but the precise prerequisites are not fully documented.
OpenCVE Enrichment