Impact
This vulnerability allows search terms entered by a user to persist in the browser’s address bar even after the user has navigated away from the search page. Because the URL bar is visible to anyone using the same machine, the stored query can inadvertently reveal sensitive or personal information that the user intended to keep private.
Affected Systems
The flaw affects Mozilla Firefox, including the main releases and ESR line, and Mozilla Thunderbird. Versions preceding Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1 are impacted.
Risk and Exploitability
The CVSS score of 8.1 reflects a high severity. The very low EPSS score of less than 1 % indicates that exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attacks would involve a local user or anyone who can view the address bar; no network or remote access is required. The impact is limited to confidential data leakage through visible query strings rather than a compromise of system integrity or availability.
OpenCVE Enrichment
EUVD
Ubuntu USN