Impact
The vulnerability arises from inadequate protection of sensitive data within Firefox for Android's Privacy component, leading to potential exposure of user information. Attackers could exploit this flaw to read data that should remain private, breaching confidentiality. The weakness aligns with CWE-200, indicating information exposure.
Affected Systems
Mozilla Firefox for Android versions prior to 143. Firefox 143 and later include the fix. No other vendors or products are impacted by this vulnerability within the current CNA data.
Risk and Exploitability
The CVSS score of 7.5 signals a high impact if exploited. The EPSS < 1% indicates a low likelihood of exploitation at this time, and the vulnerability is not listed in CISA's KEV. Likely exploitation requires user interaction or local privilege escalation, as no remote execution vector is described. Therefore, while the risk is moderate, timely patching remains critical.
OpenCVE Enrichment
EUVD