Impact
The IP Protection component in Mozilla Firefox and Thunderbird fails to protect sensitive data, resulting in information disclosure. The weakness aligns with CWE-200 and CWE-201, where data is exposed to unauthorized parties. This allows an attacker to obtain data that should remain private, potentially compromising user confidentiality.
Affected Systems
Mozilla Firefox and Thunderbird versions prior to 150 are affected. No specific earlier patch versions are identified, so all releases before 150 may be vulnerable.
Risk and Exploitability
The CVSS score for this issue is 7.5, indicating high severity. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation at this time. Attackers would need to engage the IP Protection component, likely through user interaction with a malicious resource or initiating a local action, but the exact vector is not explicit. Given the high CVSS and potential for sensitive data exposure, the risk should be considered significant for exposed systems.
OpenCVE Enrichment