Impact
Information disclosure in the Networking: WebSockets component, as identified by Mozilla. The flaw enables unauthorized parties to read data that should remain confidential, a weakness catalogued as CWE-200. No exploitation prerequisites beyond interacting with the vulnerable WebSocket component are implied, so the attack can potentially be carried out by any entity that can influence WebSocket traffic between the client and a server.
Affected Systems
Mozilla products are affected. Users of Firefox versions prior to 153 and ESR builds prior to 140.13 are vulnerable. Thunderbird users on versions older than 153 or ESR builds older than 140.13 are also impacted. Any installations of these browsers/clients that have not yet received the patch are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. While the exact attack vector is not specified in the provided information, it is inferred that an attacker would need to interact with the vulnerable WebSocket component, possibly through a malicious website or local application, to gain access to the exposed data.
OpenCVE Enrichment
Debian DLA
Debian DSA