Impact
This vulnerability involves incorrect boundary conditions in the Security: Process Sandboxing component, enabling a potential escape from the sandbox. The flaw could allow malicious content to gain elevated privileges or execute arbitrary code, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The issue affects Mozilla Firefox and Thunderbird. All versions released before Firefox 156 and Thunderbird 156 are vulnerable, and the flaw was fixed in those releases.
Risk and Exploitability
Because no EPSS score or KEV listing is available, the current exploitation likelihood is not quantified. However, the nature of the flaw—a sandbox boundary violation—suggests that an attacker could exploit it to bypass process isolation, potentially leading to a complete compromise of the host if they can supply malicious content or files to the application. The absence of a publicly known exploit does not negate the risk, and administrators should treat it as a high severity precaution.
OpenCVE Enrichment