Impact
The flaw is a misuse of cryptographic functions within the Storage: Quota Manager component. This improper handling may allow an attacker to read or otherwise manipulate the data that should be protected by encryption, potentially exposing quota information to unauthorized parties. The public description does not specify a particular exploitation method or whether remote abuse is possible, so the exploitation context remains uncertain.
Affected Systems
All releases of Firefox prior to ESR 153.4 and Firefox 157. The vulnerability is fixed in those specific builds. Users on newer ESR or stable channels should verify the installed version meets or exceeds the fixed build. No specific sub‑versions are listed, so any build older than the mentioned releases may be vulnerable.
Risk and Exploitability
No CVSS score or EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. The lack of known exploitation in the wild and the absence of exploitation details mean the risk level cannot be precisely quantified, but cryptographic misuse poses a notable confidentiality risk. The exact attack surface—whether local or remote—is not detailed in the public information.
OpenCVE Enrichment