Description
Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.
Published: 2026-08-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits the disclosure of sensitive information within Firefox for Android and Firefox Focus for Android. An attacker could potentially access data that should remain confidential, such as user credentials or browsing history. The weakness aligns with CWE-200, indicating improper handling of information that can be exposed to unauthorized parties.

Affected Systems

The affected products are Mozilla Firefox for Android and Firefox Focus for Android. Versions prior to Firefox 153.0.3 are vulnerable, as the issue was fixed in that release. All releases newer than 153.0.3 incorporate the patch.

Risk and Exploitability

The CVSS score is 6.5. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector could involve malicious web content delivered to the browser, exploiting a flaw that exposes private data. With no publicly disclosed exploits, the risk is considered moderate; however, any unpatched device could be at risk of data leakage.

Generated by OpenCVE AI on August 4, 2026 at 20:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox for Android or Firefox Focus to version 153.0.3 or later.
  • If an immediate upgrade is not possible, consider uninstalling or disabling the browser until the patch is available.
  • Enable safe browsing or block unsafe content to reduce the chance of malicious pages triggering the disclosure.

Generated by OpenCVE AI on August 4, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 04 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.
Title Information disclosure in Firefox for Android and Firefox Focus for Android
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-04T17:24:56.181Z

Reserved: 2026-08-04T12:31:09.618Z

Link: CVE-2026-18809

cve-icon Vulnrichment

Updated: 2026-08-04T17:24:51.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-04T13:17:36.680

Modified: 2026-08-18T14:49:11.260

Link: CVE-2026-18809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:15:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor