Impact
This vulnerability allows an attacker to increase privileges within Firefox for Android, potentially leading to the execution of code or access to sensitive data that was not intended for the user. The impact is limited to the scope of the application, but because it is a privilege escalation flaw, an attacker could gain elevated rights that might affect the broader device if additional exploitation is possible. The description does not specify exact mechanisms or conditions, so the full extent of the impact remains uncertain beyond the elevation of rights within the browser environment.
Affected Systems
Mozilla Firefox for Android versions prior to 155 are affected. All Android devices running an impacted Firefox installation are at risk if the browser is not updated to the patched release.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable, so an exact numeric risk estimate cannot be given. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw—privilege escalation—and the lack of disclosed constraints, it is inferred that exploitation may require the user to interact with a crafted web page or content within the browser. The attack vector is likely local or remote through the web content channel, but the specific conditions for successful exploitation are not detailed in the available information.
OpenCVE Enrichment