Impact
A flaw in Firefox for Android’s Downloads component allows an attacker to spoof the source of a downloaded file, making it appear as if it came from a trusted application or origin. This could trick users into believing a malicious file is legitimate, potentially enabling phishing or delivery of harmful content. The weakness lies in inadequate validation of the download origin and display of source information, allowing unauthenticated spoofing of file provenance.
Affected Systems
The vulnerability affects all releases of Firefox for Android earlier than version 157. The issue was corrected in Firefox 157, so any device still running a prior build is susceptible.
Risk and Exploitability
The CVSS score is not listed and EPSS is unavailable, so the precise severity cannot be quantified here. The vulnerability is not reported in CISA’s KEV catalog. The likely attack vector would involve tricking a user into interacting with a malicious download alert or link; exploitation would require the user to consent to the download. While the potential impact is significant, the lack of reported exploitation cases and its absence from KEV suggest a moderate potential for real-world attacks, contingent on user behavior.
OpenCVE Enrichment