Description
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Downloads component of Firefox for Android and allows an attacker to masquerade the origin of a file download, presenting malicious content as if it came from a trusted source. This deception can erode user confidence in the authenticity of downloaded files and may lead users to accept and execute unwanted or harmful software.

Affected Systems

Mozilla Firefox for Android versions earlier than 154 are affected; users running these builds may experience the spoofing flaw.

Risk and Exploitability

The EPSS score of 0.00172 indicates a low exploitation probability and the vulnerability is not listed in CISA KEV, indicating no known public exploits at this time. The CVSS score of 5.4 denotes a moderate severity assessment. Based on this, the risk of the spoofing flaw, while moderate, remains significant as it can lead users to accept harmful content through a likely user‑initiated download scenario.

Generated by OpenCVE AI on August 21, 2026 at 18:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox version 154 or later on Android devices
  • Disable automatic downloads from third‑party sources or schedule manual review of downloaded files
  • Organizationally enforce a policy that reviews or blocks downloads from unknown origins until the update can be applied

Generated by OpenCVE AI on August 21, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Mobile
CPEs cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:android:*:*
Vendors & Products Mozilla firefox Mobile

Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-494
References
Metrics threat_severity

None

threat_severity

Low


Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
Title Spoofing issue in the Downloads component in Firefox for Android
References

Subscriptions

Mozilla Firefox Firefox Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T14:48:43.883Z

Reserved: 2026-08-17T11:58:55.314Z

Link: CVE-2026-74975

cve-icon Vulnrichment

Updated: 2026-08-18T14:48:37.968Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:35.353

Modified: 2026-08-25T15:40:17.837

Link: CVE-2026-74975

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-18T12:23:39Z

Links: CVE-2026-74975 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:30:17Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information

  • CWE-494

    Download of Code Without Integrity Check