Description
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a clickjacking flaw in Firefox for Android’s Downloads component. Based on the description, it is inferred that a malicious web page could trick a user into interacting with unintended browser UI elements, potentially causing unwanted downloads. The impact could include unauthorized data download or other unintended actions.

Affected Systems

Mozilla Firefox for Android. Versions prior to 154 are vulnerable; the issue was resolved in Firefox 154.

Risk and Exploitability

The flaw has a CVSS score of 6.5 and an EPSS score of < 1%. No publicly disclosed exploits are known. The flaw is not listed in the CISA KEV catalog. The attack vector requires a malicious website that can manipulate page content to trick the user into accidental interactions.

Generated by OpenCVE AI on August 21, 2026 at 17:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox for Android to version 154 or later
  • Enable automatic updates so that future patches are applied without manual intervention
  • Exercise caution when interacting with web pages that may overlay UI to minimize clickjacking risk

Generated by OpenCVE AI on August 21, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Mobile
CPEs cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:android:*:*
Vendors & Products Mozilla firefox Mobile

Fri, 21 Aug 2026 12:15:00 +0000


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
Title Clickjacking issue in the Downloads component in Firefox for Android
References

Subscriptions

Mozilla Firefox Firefox Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-20T17:21:59.453Z

Reserved: 2026-08-17T11:59:06.573Z

Link: CVE-2026-74980

cve-icon Vulnrichment

Updated: 2026-08-20T15:32:35.763Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:36.873

Modified: 2026-08-25T15:40:41.990

Link: CVE-2026-74980

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-18T12:23:40Z

Links: CVE-2026-74980 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:15:05Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames