Executive brief
A vulnerability in the Firefox web browser could allow unauthorized access to information through its WebSocket networking component. WebSockets are used by the browser to maintain persistent, real-time connections with websites. If exploited, this flaw could lead to the disclosure of sensitive data, though it is considered a low-severity risk.
Technical details
An information disclosure vulnerability exists in the Networking: WebSockets component of Mozilla Firefox. The flaw allows for the unintended exposure of data during WebSocket communications. While specific root cause details are restricted in the associated bug report (Bug 2036591), the vulnerability is classified as low impact and can be triggered via network-based vectors. The issue is resolved in Firefox 153 and Firefox ESR 140.13.
Affected products
- Mozilla Firefox < 153
- Mozilla Firefox ESR < 140.13
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched