Executive brief
Mozilla Firefox contained a security flaw in its IP Protection feature, which is designed to enhance user privacy by masking IP addresses. An exploit could allow sensitive information to be disclosed, potentially undermining the privacy protections intended for the user. This issue has been resolved in version 151.
Technical details
An information disclosure vulnerability existed in the IP Protection component of Mozilla Firefox. The flaw allowed for the unintended leakage of data, though specific technical details regarding the root cause (e.g., side-channel or logic error) are restricted in the associated bug reports. The vulnerability is triggered during normal web browsing if the IP Protection feature is active. An attacker could potentially leverage this to deanonymize users or gather metadata about their connection. The issue was addressed in Firefox 151 by improving data handling within the IP Protection logic.
Affected products
- Mozilla Firefox < 151
Timeline
- 2026-05-19: advisory: Mozilla Foundation Security Advisory 2026-46 published
- 2026-05-19: patched: Fixed in Firefox 151