Description
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a malicious page or script to alter the display of the web address in the browser’s address bar, a form of user‑interface spoofing identified as CWE‑451. The attacker could make a user believe they are visiting a trusted domain when they are actually interacting with a malicious site, potentially facilitating phishing or credential theft. The impact is limited to the user interface and does not directly grant code execution or privilege escalation, but it can lead to social engineering attacks.

Affected Systems

Mozilla’s Firefox and Thunderbird clients are affected; the flaw was fixed in Firefox 153 and Thunderbird 153, meaning all earlier releases are vulnerable. No specific sub‑versions beyond the 153 cutoff are listed.

Risk and Exploitability

The CVSS score of 6.5 denotes moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not referenced in the CISA KEV catalog. Because the flaw requires an attacker to load a crafted web page or script that manipulates the address bar, it is presumed to be a local or network‑based attack, dependent on the user accessing malicious content. The risk is therefore mainly to end users who may be misled, rather than to the attacker’s control over the system.

Generated by OpenCVE AI on August 4, 2026 at 05:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox or Thunderbird version 153 or later to receive the issued fix.
  • If upgrading immediately is not possible, configure the browser or use an extension to disable or restrict pages from modifying the address bar or enable strict content‑security settings that prevent UI manipulation.
  • Educate users to verify the actual URL in the address bar and report any suspicious changes; monitor for reports of misleading address bar content.

Generated by OpenCVE AI on August 4, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153. Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.
Title Spoofing issue in the Address Bar component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:08.765Z

Reserved: 2026-07-20T21:57:37.813Z

Link: CVE-2026-16403

cve-icon Vulnrichment

Updated: 2026-07-22T17:25:46.392Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:15.693

Modified: 2026-07-24T16:44:54.933

Link: CVE-2026-16403

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-21T12:38:15Z

Links: CVE-2026-16403 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information