Mozilla Firefox and Firefox ESR Same-Origin Policy Bypass Vulnerability in the DOM: Workers Component

Vulnerability

A same-origin policy bypass vulnerability has been identified in the DOM: Workers component of Mozilla Firefox. This issue affects Firefox versions prior to 145 and Firefox ESR versions prior to 140.5. The vulnerability allows for unauthorized cross-origin interactions by bypassing the same-origin policy, which could lead to potential security risks such as data leakage or manipulation.

Impact

Exploitation of this vulnerability allows for a same-origin policy bypass, enabling cross-origin interactions that could lead to data leakage or manipulation.

Remediation

Users can upgrade to Firefox 145 or Firefox ESR 140.5 to address this vulnerability.

Added: Nov 11, 2025, 4:26 PM
Updated: Nov 11, 2025, 4:26 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.8
exploitability
4.4
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.