Impact
The vulnerability originates in the WebExtensions component of Firefox for Android and allows an attacker to read data that the application should not disclose. The impact is a disclosure of potentially sensitive information such as user data, session information, or other private data that resides on the device. The weakness is an information exposure flaw that can undermine confidentiality.
Affected Systems
All installations of Mozilla Firefox for Android that run a version older than 155 are affected, as the fix was introduced in Firefox 155. Existing users on any earlier releases should be notified of the risk.
Risk and Exploitability
The information disclosure is not listed in CISA's KEV catalog and its EPSS score is not available, indicating limited data on exploitation likelihood. The attack vector is not explicitly stated; based on the component involved, it is inferred that the vulnerability requires local or privileged access to the device, potentially through installed extensions or a malicious extension. Without confirmed exploitation data, the risk is considered moderate to low, but the lack of patching still allows data leakage.
OpenCVE Enrichment