Impact
This vulnerability is a spoofing issue located in the Document Object Model navigation component of Mozilla Firefox and Thunderbird. Based on the description, it is inferred that a malicious website can manipulate the navigation UI so that a user believes they are interacting with a legitimate, trusted interface, potentially leading them to click links or enter credentials. The weakness is primarily an input handling flaw, corresponding to the CWE classifications for information exposure through spoofing and improper neutralization of input.
Affected Systems
The affected applications are Mozilla Firefox and Mozilla Thunderbird. All versions earlier than Firefox 156 and the ESR 153.3 release, as well as Thunderbird earlier than 156, are impacted. Users on these versions should verify their current build and plan to upgrade to the fixed releases.
Risk and Exploitability
The flaw is client‑side and requires an end‑user to load a crafted page containing malicious DOM content. Based on the description, it is inferred that no explicit execution context or environment is specified, implying the attack requires user interaction with a malicious web page. No public exploit code is cited in the available data, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been observed in known exploitation campaigns. The EPSS score of less than 1% indicates a very low probability of widespread exploitation, yet the potential for phishing or click‑jacking makes it a moderate threat for users who frequently visit untrusted websites.
OpenCVE Enrichment