Impact
Information disclosure occurs in the WebRTC component of Mozilla browsers. The flaw allows an attacker to read data that should remain confidential, compromising user privacy and potentially revealing sensitive information. The weakness is identified by CWE‑1021 and CWE‑201, indicating failure to maintain information boundaries in client‑side API usage.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird, including ESR releases, are affected. Versions prior to Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1 contain the unpatched vulnerability. Subsequent releases contain the fix.
Risk and Exploitability
The EPSS score of 0.00264 indicates a very low probability of exploitation, while the CVSS score of 7.5 classifies the issue as high severity. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation. The likely attack vector is client‑side; an attacker would need to host a malicious web page that leverages WebRTC APIs to trigger the information disclosure.
OpenCVE Enrichment