Executive brief
A security flaw was identified in the Firefox web browser for Android devices. This issue involves the component that handles browser extensions and could allow a malicious website to trick users into performing unintended actions, such as clicking buttons or changing settings, by overlaying deceptive visual elements. Users are advised to update to version 153 or later to resolve this issue.
Technical details
A clickjacking vulnerability was discovered in the WebExtensions component of Firefox for Android. The flaw allows an attacker to potentially overlay or frame sensitive browser extension interfaces, leading to UI redress attacks where a user is tricked into performing actions they did not intend. This typically occurs when the application fails to properly implement or enforce frame-busting protections or security headers for extension-related UI. The vulnerability is resolved in Firefox version 153. An attacker would require a user to visit a specially crafted malicious webpage to exploit this issue.
Affected products
- Mozilla Firefox for Android before 153
Timeline
- 2026-07-21: advisory
- 2026-07-21: disclosed
- 2026-07-21: patched