Sceawere

Vulnerability Detail

CVE-2026-96869UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Firefox Networking Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
12h ago
Vendor
Mozilla
Product
Firefox
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-29T13:17:53.610Z",
  "pubdate": "2026-09-29T13:17:53.610Z",
  "executiveSummary": "This vulnerability involves an information disclosure flaw identified within the Networking component of the Firefox browser architecture.\nThe vulnerability allows an unauthorized actor to access sensitive data that should be restricted by the browser's security boundary.\nThe scope of impact affects Firefox, Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.\nThis flaw presents a significant risk to user privacy and data integrity, as it may permit the unauthorized extraction of cached data, session tokens, or other sensitive information handled by the networking stack.\nExploitation typically requires the victim to interact with malicious or compromised web content designed to trigger the flaw within the browser's request/response handling logic.\nThe vulnerability does not necessarily require advanced administrative privileges, but successful exploitation depends on the target's interaction with specific network-layer operations facilitated by the browser.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper implementation or state management error within the Networking component of the Firefox browser. Specifically, the flaw exists within the mechanisms responsible for parsing, storing, or transmitting network resources, leading to a breakdown in information isolation.\nThe Networking component handles various protocols and handles data streams between the browser and remote endpoints. An information disclosure vulnerability in this context typically indicates that the component fails to properly sanitize or restrict access to data buffers, headers, or cached response bodies. Under certain conditions, this component may leak cross-origin data or internal networking state information to a malicious actor.\nThe attack flow generally involves the following sequence: 1) A threat actor deploys a malicious document or webpage that induces a specific network transaction. 2) The browser’s Networking component attempts to process the request or response, triggered by the malicious script or resource. 3) Due to the vulnerability, the internal logic fails to maintain strict boundaries, causing the sensitive information to be improperly exposed to the attacker’s context. 4) The attacker extracts this information, potentially gaining access to credentials, session state, or metadata that should have remained protected within the browser's sandbox or origin policy.\nThis vulnerability is present in Firefox, Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. The vulnerability does not appear to require authentication on the part of the attacker, as it is triggered through the standard browser-to-web interaction model. Privilege requirements are effectively zero, as the attack leverages the browser's inherent capabilities to process web content. The network exposure is broad, as any content reachable by the browser's networking stack can potentially be used to weaponize this vulnerability if the victim navigates to a malicious URL.\nPost-exploitation impact includes the potential for identity theft, session hijacking, or the leakage of sensitive user data, depending on what the networking component is currently handling at the time of the exploit. Because the Networking component sits at the core of all web-based communication for the browser, the exploit scope is restricted only by the information passing through the affected protocols."
}
CVE-2026-96869: Firefox Networking Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere