Impact
A flaw was identified in Firefox Focus for Android, and the vendor issued a fix in version 155. The description does not specify the exact weakness or exploitation method, so the impact cannot be precisely quantified from the data provided. Based on typical patterns in the Firefox family, such issues can range from memory corruption leading to application crashes to more severe code‑execution or data‑exposure problems. Because the advisory does not mention exploitation in the wild or listing in CISA’s KEV catalog, the vulnerability is not known to have been actively targeted at this time.
Affected Systems
All installations of Firefox Focus for Android that are older than version 155 are potentially affected. No additional sub‑release information is provided, so any release prior to the fix is considered vulnerable unless otherwise documented by Mozilla.
Risk and Exploitability
The CVSS score and EPSS score are not available, but the KEV status indicates the vulnerability is not listed in CISA’s KEV catalog. Without evidence of a live exploit or high‑impact indicator, the risk is uncertain but likely low. Attackers would need access to the vulnerable app to exploit it, yet the lack of publicly reported exploitation efforts suggests that the probability of exploitation is limited. Consequently, the overall threat remains moderate until further details emerge.
OpenCVE Enrichment