CVE-2026-74975
Undergoing Analysis Undergoing Analysis - In Progress

Spoofing in Firefox for Android Downloads

Vulnerability report for CVE-2026-74975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Mozilla Corporation

Description

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mozilla firefox 154

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-451 The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a spoofing vulnerability in Firefox for Android where a download confirmation notification could be overlaid over other websites. It tricks users into believing the notification came from a trusted site like Google.com when it actually originated from a malicious source.

Detection Guidance

This vulnerability involves a spoofing issue in Firefox for Android's Downloads component where download confirmation notifications could be overlaid over other websites. To detect it, check if your Firefox for Android version is below 154. If so, the device may be vulnerable.

Impact Analysis

This vulnerability could lead to phishing attacks by misleading users into trusting fake download confirmations. Users might unknowingly download malicious files or share sensitive information, thinking they are interacting with a legitimate site.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling phishing attacks that trick users into downloading malicious files. Such attacks may lead to unauthorized data access or disclosure, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Update Firefox for Android to version 154 or later immediately to patch the vulnerability. Avoid downloading files from untrusted sources until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart