Mozilla Firefox Same-Origin Policy Bypass Vulnerability in CSS Parsing Component

Vulnerability

A same-origin policy bypass vulnerability has been identified in the CSS Parsing and Computation component of Mozilla Firefox. This issue affects versions of Firefox prior to 148.0.2. The vulnerability arises from a flaw in how the browser's CSS parsing engine handles same-origin policy, potentially allowing maliciously crafted styles to be applied in a way that bypasses security restrictions.

Impact

Exploitation of this vulnerability could lead to a bypass of the same-origin policy, allowing for cross-origin interactions that are normally restricted, which could be exploited to manipulate or access resources in a way that violates the intended security boundaries.

Remediation

Users can upgrade to Firefox version 148.0.2 or later to address this vulnerability.

Added: Mar 10, 2026, 6:23 PM
Updated: Mar 10, 2026, 6:23 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
3.1
exploitability
4.4
remediation
7.7
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.