Impact
A flaw in Firefox for Android allows an attacker to cause the browser to treat network traffic as coming from a different origin than it actually does. This spoofing of web requests or responses can undermine authentication and authorization checks that the browser relies on to protect user sessions. The vulnerability falls under CWE-290 and primarily threatens the confidentiality and integrity of user data accessed through the browser.
Affected Systems
Mozilla Firefox for Android versions released before 153 are vulnerable. The issue applies to all Android devices running any browser version up to 152, regardless of the underlying Android OS version. The fix was incorporated in Firefox 153, so any installation that has not been updated to that release or later remains at risk.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is currently rare in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector, inferred from the vulnerability description, involves a remote attacker delivering a malicious web resource that the user visits; this can trigger the spoofing behavior without requiring additional privileges.
OpenCVE Enrichment