Impact
The vulnerability is a clickjacking flaw in Firefox for Android’s Downloads component. Based on the description, it is inferred that a malicious web page could trick a user into interacting with unintended browser UI elements, potentially causing unwanted downloads. The impact could include unauthorized data download or other unintended actions.
Affected Systems
Mozilla Firefox for Android. Versions prior to 154 are vulnerable; the issue was resolved in Firefox 154.
Risk and Exploitability
The flaw has a CVSS score of 6.5 and an EPSS score of < 1%. No publicly disclosed exploits are known. The flaw is not listed in the CISA KEV catalog. The attack vector requires a malicious website that can manipulate page content to trick the user into accidental interactions.
OpenCVE Enrichment