@screaminggoat : thank you for responding!
I'm not sure whether I should be the one to ask for a CVE registration. I prefer to leave that to Mozilla.
I repeatedly asked them if they were able to reproduce it, but there was no answer (adding my former experiences with vulnerability reports, I would not be surprised if zillions of vulnerabilities remain unpatched because of miscommunications and misunderstandings).
It tested this bug on a number of devices owned by different people, but most (if not all) of those devices had their configuration secured as good as possible by me, so I cannot fully exclude that I'm a common factor - while others may not be able te reproduce it. That could significantly reduce severity.
By going public I hope to get some acknowledgements that this vulnerability reproduces (perhaps I should have stated that louder, but the longer a toot, the less it gets read).
So I prefer to wait and see what (if anything) happens. Thanks again!
@mozilla