Impact
The vulnerability is a mitigation bypass in Firefox's Privacy: Anti‑Tracking component. It allows malicious content or users to disable or circumvent the anti‑tracking enforcement, potentially undermining the browser’s privacy protections. This flaw is categorized as a Security Misconfiguration (CWE‑693).
Affected Systems
Mozilla Firefox on all versions prior to 147.0.2 is affected. The fix was released in Firefox 147.0.2. No other products or versions are listed in the CVE data.
Risk and Exploitability
CVSS v3.1 score 6.5 indicates moderate severity. EPSS <1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not in the CISA KEV catalog. Attack vector is not explicitly stated in the CVE; based on the limited description it is inferred that local or remote exploitation via crafted web content or malicious user interaction may be possible. No additional privileges or conditions are identified in the provided data.
OpenCVE Enrichment