Impact
The vulnerability is an information disclosure flaw in the networking component used by Mozilla Firefox and Thunderbird. It allows a malicious actor to view data that should remain private, such as network configuration or traffic details, thereby compromising user confidentiality. The weakness stems from insufficient access control and improper authorization around the networking subsystem and is classified as CWE‑200 and CWE‑201. The CVSS score of 4.3 indicates a low severity impact.
Affected Systems
Mozilla Firefox and Firefox ESR releases prior to version 156 and 153.3 respectively, as well as Mozilla Thunderbird and Thunderbird ESR releases prior to version 156 and 153.3.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.3 confirms that the flaw poses a low severity risk. Based on the description, the likely attack vector is local or requiring elevated permissions within the affected application, and no active exploitation activity is reported. While the exploitation chances remain minimal, the potential for confidential data leakage warrants timely remediation.
OpenCVE Enrichment