A corrective release of Firefox 96.0.3 is now available, along with a new release of the long-term support branch, Firefox 91.5.1, which addresses a bug that, under certain circumstances, led to the transmission of unnecessary data to the telemetry collection server. The overall share of unwanted data among all event logs on the telemetry servers is estimated at 0.0013% for the desktop version of Firefox, 0.0005% for the Android version of Firefox, and 0.0057% for Firefox Focus.
Under normal conditions, the browser transmits 'search codes' assigned by search service providers, allowing insight into how many queries the user has sent through the partner search system. The search codes alone do not reveal the contents of the search queries and do not include any identifiable or unique information. When accessing a search engine, the search code is indicated in the URL, and together with telemetry, counters for the search codes are transmitted, allowing determination that a valid code was sent during the request and that the search engine was not substituted by malware.
The essence of the identified problem is that if a user accidentally edits part of the URL with the search code, the contents of this modified field will also be sent to server telemetry. The danger lies in accidental unintended changes; for example, if a user inadvertently adds 'example@example.com' from the clipboard to the field '&client=firefox-b-d', the value 'firefox-b-dexample@example.com' will be transmitted in the telemetry.
Source: opennet.ru
