Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 145
A same-origin policy bypass vulnerability has been identified in the DOM Notifications component of Mozilla Firefox. This issue affects Firefox versions prior to 145 and Firefox ESR versions prior to 140.5. The vulnerability allows for unauthorized access or manipulation of notifications across different origins, potentially leading to privacy concerns or exploitation of notification-based features.
Exploitation of this vulnerability allows for a same-origin policy bypass, enabling cross-origin interactions with the Notifications component, which could be misused to access or manipulate notification data from different origins.
Users can upgrade to Firefox 145 or Firefox ESR 140.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.