Impact
The vulnerability is a site isolation flaw in the Reader Mode component that can allow an attacker to bypass the separation between browsing contexts and potentially read data that should be protected.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. The fix is available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Risk and Exploitability
The CVSS score is 5.4. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. A likely attack would require the use of Reader Mode and would target a user who enables the feature or visits a site that automatically triggers it. Because no real-world exploitation is reported and the component is not widely exposed, the risk of deployment is low but the impact of a successful attack could involve unauthorized access to data from a browsing context.
OpenCVE Enrichment