Description
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Spoofing
Action: Immediate Patch
AI Analysis

Impact

A flaw in Firefox for Android’s Downloads component allows an attacker to spoof the source of a downloaded file, making it appear as if it came from a trusted application or origin. This could trick users into believing a malicious file is legitimate, potentially enabling phishing or delivery of harmful content. The weakness lies in inadequate validation of the download origin and display of source information, allowing unauthenticated spoofing of file provenance.

Affected Systems

The vulnerability affects all releases of Firefox for Android earlier than version 157. The issue was corrected in Firefox 157, so any device still running a prior build is susceptible.

Risk and Exploitability

The CVSS score is not listed and EPSS is unavailable, so the precise severity cannot be quantified here. The vulnerability is not reported in CISA’s KEV catalog. The likely attack vector would involve tricking a user into interacting with a malicious download alert or link; exploitation would require the user to consent to the download. While the potential impact is significant, the lack of reported exploitation cases and its absence from KEV suggest a moderate potential for real-world attacks, contingent on user behavior.

Generated by OpenCVE AI on September 29, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 157 or later on all Android devices
  • Verify that download notifications correctly display the source before accepting a file
  • Disable or limit automatic downloads from unknown or untrusted origins until applying the patch

Generated by OpenCVE AI on September 29, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-264

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
Title Spoofing issue in the Downloads component in Firefox for Android
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:31.480Z

Reserved: 2026-09-26T19:18:40.744Z

Link: CVE-2026-100823

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:47.603

Modified: 2026-09-29T13:17:47.603

Link: CVE-2026-100823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T18:45:10Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-264