Junglewise Threat Intelligence

CVE-2026-16403: Mozilla Firefox spoofing in Address Bar

CVE-2026-16403 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability in the Firefox web browser's address bar could allow a malicious website to misrepresent its identity. By spoofing the address bar, an attacker could trick users into believing they are visiting a legitimate site, such as a bank or email provider, potentially leading to credential theft or phishing. This issue was resolved in Firefox version 153.

Technical details

A spoofing vulnerability existed in the Address Bar component of Mozilla Firefox. The flaw allowed a malicious site to potentially manipulate the displayed URL or security indicators in the browser's address bar, leading to user deception. While specific root cause details (such as race conditions or character handling issues) are restricted in the associated Bugzilla report, the impact is categorized as a low-severity spoofing issue. The vulnerability is resolved in Firefox 153.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched

References

Related threats