Impact
The vulnerability resides in the Downloads component of Firefox for Android and allows an attacker to masquerade the origin of a file download, presenting malicious content as if it came from a trusted source. This deception can erode user confidence in the authenticity of downloaded files and may lead users to accept and execute unwanted or harmful software.
Affected Systems
Mozilla Firefox for Android versions earlier than 154 are affected; users running these builds may experience the spoofing flaw.
Risk and Exploitability
The EPSS score of 0.00172 indicates a low exploitation probability and the vulnerability is not listed in CISA KEV, indicating no known public exploits at this time. The CVSS score of 5.4 denotes a moderate severity assessment. Based on this, the risk of the spoofing flaw, while moderate, remains significant as it can lead users to accept harmful content through a likely user‑initiated download scenario.
OpenCVE Enrichment