Impact
The vulnerability in the Profile Backup component can allow a sandbox escape. By bypassing the sandbox, an attacker could gain broader access to files that the component handles, such as backup data and possibly other locally stored configuration. The CVE description does not state that arbitrary code execution or elevated system privileges are achieved, so the impact is limited to the sandbox’s surface area. (The potential for more extensive damage is inferred from typical sandbox escape behavior but is not directly supported by the provided text.)
Affected Systems
Mozilla Firefox and Mozilla Thunderbird, for all releases earlier than version 156. The flaw was addressed in Firefox 156 and Thunderbird 156, so those and later releases are not vulnerable.
Risk and Exploitability
The EPSS score is below 1%, indicating a very low probability of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog, and the CVSS score of 9.8 classifies it as critical. The data does not disclose a specific attack vector; a likely scenario involves user-initiated backup operations that could be manipulated with untrusted input. Overall, the risk remains high, but remediation is recommended to prevent potential sandbox escape before additional details emerge.
OpenCVE Enrichment