Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
https://www.mozilla.org/security/advisories/mfsa2022-49/
https://www.mozilla.org/security/advisories/mfsa2022-48/