Impact
Based on the description, it is inferred that a malicious web page could bypass the browser’s popup blocker, letting normally suppressed popups appear. This is a CWE‑807 flaw, and also a CWE‑693 flaw, indicating improper control of a critical security feature. The vulnerability does not grant direct code execution or data access. The CVSS score of 8.8 indicates a high severity vulnerability.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected. Versions earlier than Firefox 156 or Firefox ESR 153.3, and earlier than Thunderbird 156 or Thunderbird ESR 153.3 remain vulnerable.
Risk and Exploitability
The CVSS score is 8.8, indicating high risk to confidentiality, integrity, and availability. The EPSS score of <1% implies a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the bypass can be triggered by visiting a malicious site and requires no special privileges.
OpenCVE Enrichment