Executive brief
A spoofing vulnerability was identified in the Firefox web browser's core HTML component. This flaw could allow a malicious website to misrepresent information or content to the user, potentially leading to phishing or other deceptive attacks. Users are advised to update to the latest version of the browser to maintain security.
Technical details
A spoofing vulnerability exists in the Mozilla Firefox DOM: Core & HTML component. The flaw allows for potential content or UI spoofing, though specific root cause details are restricted in the associated Bugzilla report (Bug 2035027). An attacker could leverage this to deceive users by presenting fraudulent information as legitimate within the browser context. The vulnerability is categorized as low impact by Mozilla and was resolved in Firefox 152. No authentication is required for exploitation beyond a user visiting a malicious site.
Affected products
- Mozilla Firefox < 152
Timeline
- 2026-06-16: advisory: Mozilla Foundation Security Advisory 2026-57 published.
- 2026-06-16: patched: Fixed in Firefox 152.