Impact
This vulnerability permits the disclosure of sensitive information within Firefox for Android and Firefox Focus for Android. An attacker could potentially access data that should remain confidential, such as user credentials or browsing history. The weakness aligns with CWE-200, indicating improper handling of information that can be exposed to unauthorized parties.
Affected Systems
The affected products are Mozilla Firefox for Android and Firefox Focus for Android. Versions prior to Firefox 153.0.3 are vulnerable, as the issue was fixed in that release. All releases newer than 153.0.3 incorporate the patch.
Risk and Exploitability
The CVSS score is 6.5. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector could involve malicious web content delivered to the browser, exploiting a flaw that exposes private data. With no publicly disclosed exploits, the risk is considered moderate; however, any unpatched device could be at risk of data leakage.
OpenCVE Enrichment