Impact
Uninitialized memory in the Storage: Quota Manager component can allow an attacker to read data that was not intended for that process, potentially revealing sensitive information or causing unpredictable behaviour. The weakness corresponds to improper initialization of variables, identified as CWE-665.
Affected Systems
Mozilla:Firefox is affected. The vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. All earlier builds that have not applied these patches are at risk.
Risk and Exploitability
The CVSS score is not published, and the EPSS score is not available, so precise severity and likelihood are unknown. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is local; any code that triggers quota management in the browser can read uninitialized memory, so a malicious website or local process could exploit it. Given the lack of public exploits and high complexity of inducing the exact memory state, the risk is considered moderate until the patch is applied.
OpenCVE Enrichment