Impact
A race condition in the browser’s handling of tab contexts can allow private browsing tabs to open inside a standard browsing window, exposing users’ confidential information. This flaw provides an unauthorized view into private content, constituting a privacy leak. The weakness falls under CWE‑362, indicating a timing flaw between concurrent operations.
Affected Systems
The flaw affects Mozilla Firefox and Mozilla Thunderbird browsers. Versions prior to Firefox 135 and Firefox ESR 128.7, and Thunderbird prior to Thunderbird 135 and Thunderbird ESR 128.7 are vulnerable. Red Hat Enterprise Linux packages that embed these browser components may also be affected if the bundled versions are out of date.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate. An EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the flaw is not currently listed in the CISA KEV catalog. The likely attack vector is local, requiring the attacker to have access to a user session or the browser process to trigger the race condition. Because the flaw depends on user activity and precise timing, the likelihood of successful exploitation remains low, but it should not be ignored because of the potential privacy impact.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD
Ubuntu USN