Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 148.0.2
A same-origin policy bypass vulnerability has been identified in the CSS Parsing and Computation component of Mozilla Firefox. This issue affects versions of Firefox prior to 148.0.2. The vulnerability arises from a flaw in how the browser's CSS parsing engine handles same-origin policy, potentially allowing maliciously crafted styles to be applied in a way that bypasses security restrictions.
Exploitation of this vulnerability could lead to a bypass of the same-origin policy, allowing for cross-origin interactions that are normally restricted, which could be exploited to manipulate or access resources in a way that violates the intended security boundaries.
Users can upgrade to Firefox version 148.0.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.