Impact
A flaw in the Privacy component of Firefox for Android may leak sensitive browsing data and preferences, exposing user information to attackers. The weakness corresponds to CWE‑200, an information‑disclosure vulnerability that can compromise confidentiality by allowing unintended data access. The impact is limited to data visible or loggable by the component, but it can expose user preferences, URL histories and other sensitive settings if exploited.
Affected Systems
Mozilla Firefox for Android versions prior to 153 are vulnerable, as the defect was patched in Firefox 153. Any device running an older release of the Android application is affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high severity for information disclosure. The EPSS score of less than 1% suggests a low probability of exploitation in the near term, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is likely local client‑side exploitation through malicious web content or scripts executed within Firefox, which could be triggered by a user visiting a crafted site or by an app that injects content into the browser.
OpenCVE Enrichment