An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1717672 | vendor advisory issue tracking |
https://www.mozilla.org/security/advisories/mfsa2025-51/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-52/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-53/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-54/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2025-55/ | vendor advisory |