Impact
This CVE refers to an issue in the Profile Backup component of Mozilla Firefox and Thunderbird. The advisory does not detail the precise flaw, but it implies that the backup process may mishandled sensitive data or exposed it to unauthorized access. The absence of a defined exploit scenario leaves the exact impact uncertain, yet the nature of the component suggests that its code path could allow either data leakage or backup integrity corruption if misused.
Affected Systems
Mozilla Firefox versions prior to 155 and the ESR 153.2 branch, and Mozilla Thunderbird versions prior to 155 and the ESR 153.2 branch, are identified as affected. All releases after these versions contain the fix, so updating the application removes the vulnerability.
Risk and Exploitability
The CVSS score is 9.8, EPSS is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The advisory does not describe a specific attack vector, so it is reasonable to infer that exploitation, if possible, would require local or semi‑local conditions such as access to the user’s profile directory or execution of the backup operation. The lack of detailed exploitation information indicates a lower immediate threat, though systematic monitoring is advisable.
OpenCVE Enrichment