Description
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Firefox for Android allows an attacker to cause the browser to treat network traffic as coming from a different origin than it actually does. This spoofing of web requests or responses can undermine authentication and authorization checks that the browser relies on to protect user sessions. The vulnerability falls under CWE-290 and primarily threatens the confidentiality and integrity of user data accessed through the browser.

Affected Systems

Mozilla Firefox for Android versions released before 153 are vulnerable. The issue applies to all Android devices running any browser version up to 152, regardless of the underlying Android OS version. The fix was incorporated in Firefox 153, so any installation that has not been updated to that release or later remains at risk.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is currently rare in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector, inferred from the vulnerability description, involves a remote attacker delivering a malicious web resource that the user visits; this can trigger the spoofing behavior without requiring additional privileges.

Generated by OpenCVE AI on August 4, 2026 at 05:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox for Android to version 153 or newer.
  • Install the latest Firefox release from the official app store to ensure the vulnerability is patched.
  • Keep the device’s operating system and security patches up to date to reduce the overall attack surface.

Generated by OpenCVE AI on August 4, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
Title Spoofing issue in Firefox for Android
References

Subscriptions

Mozilla Firefox Firefox Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T17:27:29.188Z

Reserved: 2026-07-20T21:57:40.223Z

Link: CVE-2026-16404

cve-icon Vulnrichment

Updated: 2026-07-22T17:26:33.416Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:15.803

Modified: 2026-07-24T16:24:30.970

Link: CVE-2026-16404

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-21T12:38:16Z

Links: CVE-2026-16404 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing