Impact
The vulnerability is an information disclosure flaw in Firefox’s Networking: HTTP component. An attacker could read data that should remain confidential, such as personal information or authentication tokens, when the browser processes crafted HTTP traffic. The weakness arises from the component failing to mask sensitive data before exposure. This flaw can lead to privacy violations and may facilitate account takeover if accessed privileged information.
Affected Systems
All Firefox installations before version 155 and the ESR branch before 153.2 are affected. The patch was delivered in Firefox 155 and ESR 153.2. Users on newer releases are not affected.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, implying that widespread exploitation is not currently documented. The likely attack vector is a malicious web page or a network proxy that manipulates HTTP requests or responses reaching the vulnerable component. Because the flaw requires the victim to use an affected browser and to load content that exercises the code path, the risk to organisations with strict confidentiality requirements remains moderate to high despite the low known exploitation incidence.
OpenCVE Enrichment