Firefox flaw allowed tracking even in private browsing

Researchers at Fingerprint have found a bug affecting all Firefox-based browsers. The issue lies in IndexedDB and can be used to fingerprint the running browser process even in contexts where users expect stronger isolation, such as Firefox private browsing. The finding was disclosed to Mozilla and the Tor Project, and is fixed in Firefox 150 and ESR 140.10.0.

What this means for your organisation

This is not a vulnerability that gives attackers access to systems; it is a privacy problem. Private browsing is often treated as a control in its own right, both by staff and by customers visiting your services. When the isolation does not hold, an assumption that organisations may have built assessments on falls away, for instance in data protection impact assessments. For organisations with staff in exposed roles, cross-context traceability can also have an operational dimension.

Berigo recommends

  • Roll out Firefox 150 or ESR 140.10.0 across company machines through normal software distribution.
  • Review whether any internal routines or privacy assessments assume private browsing provides isolation.
  • Make sure the ESR channel is actually being maintained; it often lags in centrally managed estates.
  • Consider whether staff in exposed roles need stronger measures than the browser's own privacy features.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch