Impact
The Session Restore component processes stored session data when the application starts. The vulnerability is a privilege‑elevation flaw that allows a local user to gain higher privileges within the running application. It is classified as CWE‑269. The CVE description does not detail the exact mechanism, but it states that the flaw can be exploited until the release of Firefox 156, ESR 153.3, or Thunderbird 156. It is inferred that an attacker could craft a session restore file to trigger the flaw, because session restore files are read during startup.
Affected Systems
All Mozilla Firefox releases prior to version 156, all Firefox ESR releases older than 153.3, and all Mozilla Thunderbird releases older than 156 are affected. Upgrading to Firefox 156 or later, or to Firefox ESR 153.3 or later, and upgrading Thunderbird to 156 or later resolves the issue.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity for privilege escalation. The EPSS score is not available, so exploitation likelihood is unknown. The flaw does not require network access and may be triggered locally; this is inferred from the nature of session restoration. The vulnerability is not listed in the CISA KEV catalog. Because the flaw could allow an attacker to run code with the privileges of the user running the application, it poses a significant risk to users who run the affected products.
OpenCVE Enrichment