An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12.
https://www.mozilla.org/security/advisories/mfsa2025-53/
https://www.mozilla.org/security/advisories/mfsa2025-52/