Junglewise Threat Intelligence

CVE-2026-8966: Mozilla Firefox information disclosure in IP Protection

CVE-2026-8966 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox contained a security flaw in its IP Protection feature, which is designed to enhance user privacy by masking IP addresses. An exploit could allow sensitive information to be disclosed, potentially undermining the privacy protections intended for the user. This issue has been resolved in version 151.

Technical details

An information disclosure vulnerability existed in the IP Protection component of Mozilla Firefox. The flaw allowed for the unintended leakage of data, though specific technical details regarding the root cause (e.g., side-channel or logic error) are restricted in the associated bug reports. The vulnerability is triggered during normal web browsing if the IP Protection feature is active. An attacker could potentially leverage this to deanonymize users or gather metadata about their connection. The issue was addressed in Firefox 151 by improving data handling within the IP Protection logic.

Affected products

  • Mozilla Firefox < 151

Timeline

  • 2026-05-19: advisory: Mozilla Foundation Security Advisory 2026-46 published
  • 2026-05-19: patched: Fixed in Firefox 151

References

Related threats