Impact
The vulnerability is an information disclosure flaw within the Networking: JAR component of Mozilla Firefox. An attacker can cause the browser to reveal sensitive data that it would otherwise keep private, such as authentication credentials or local files. The issue is aligned with CWE‑200, Information Exposure, and can compromise confidentiality when exploited.
Affected Systems
This flaw affects Mozilla Firefox installations on all operating systems where the Networking: JAR component is enabled. The fixes are available in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Systems running earlier releases of these branches are vulnerable.
Risk and Exploitability
EPSS data is not published for this issue and it is not listed in the CISA KEV catalog, indicating no current known exploitation campaign. However, because the flaw allows information to escape over the network, the likely attack vector is indirect remote exploitation via user interaction with a malicious JAR resource. The CVSS score is not supplied, but the presence of a patch in multiple release lines and the lack of detection in KEV suggest the risk is moderate to high for systems that remain unpatched. Immediate attention is advised to upgrade or apply the fix.
OpenCVE Enrichment