Impact
A flaw was identified in Firefox Focus for Android, and the vendor issued a fix in version 155. The description does not specify the exact weakness or exploitation method, so the impact cannot be precisely quantified from the data provided. Based on the CWE-20 and CWE-200 designations, the vulnerability involves input validation flaws and potential information disclosure.
Affected Systems
All installations of Firefox Focus for Android that are older than version 155 are potentially affected. No additional sub‑release information is provided, so any release prior to the fix is considered vulnerable unless otherwise documented by Mozilla.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity vulnerability. The EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation. Therefore, the risk is uncertain and likely low. The likely attack vector is local access to the application, requiring the user to run Firefox Focus or to provide the app with malicious inputs. Based on these data, the overall threat remains low until more details are available.
OpenCVE Enrichment