Description
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to overlay the browser interface through a transparent page so that a user unknowingly clicks a malicious element. This can lead the user to perform unintended actions within Firefox for Android.

Affected Systems

Affected systems include Mozilla Firefox on Android with any build prior to version 154. The descriptive title and reference notes confirm that the flaw specifically impacted the Android rendering of web content.

Risk and Exploitability

Exploitability is straightforward, requiring only a malicious web page visited by a user. EPSS score is not available, and the vulnerability is not listed in CISA KEV; the CVSS score is 6.5. The issue is mitigated entirely by upgrading to Firefox 154 or later, which removes the flaw. Without a patch, attackers can continue to clickjacking the device UI at will.

Generated by OpenCVE AI on August 18, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or later on all affected Android devices.
  • Review and apply any additional security patches from Mozilla for Firefox promptly.
  • Avoid browsing untrusted sites or clicking on unfamiliar links on your Android device, which reduces exposure to potential clickjacking content.

Generated by OpenCVE AI on August 18, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:15:00 +0000


Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Mobile
CPEs cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:android:*:*
Vendors & Products Mozilla firefox Mobile

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
Title Clickjacking issue in Firefox for Android
References

Subscriptions

Mozilla Firefox Firefox Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T19:13:58.944Z

Reserved: 2026-08-17T11:58:01.750Z

Link: CVE-2026-74951

cve-icon Vulnrichment

Updated: 2026-08-18T19:13:17.180Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:31.963

Modified: 2026-08-19T15:08:26.010

Link: CVE-2026-74951

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T12:23:36Z

Links: CVE-2026-74951 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T22:15:04Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames