Executive brief
A spoofing vulnerability was identified in Firefox for Android that could allow a malicious website to misrepresent information to the user. This type of flaw is typically used in phishing attacks to trick users into believing they are interacting with a legitimate site or interface. Users should update to version 153 or later to resolve this issue.
Technical details
A spoofing vulnerability exists in Firefox for Android prior to version 153. While specific technical details are restricted in the associated Bugzilla report (Bug 2020253), the flaw allows for the misrepresentation of UI elements or content, potentially facilitating phishing or social engineering attacks. The vulnerability is categorized as low impact by Mozilla. It is fixed in Firefox 153.
Affected products
- Mozilla Firefox for Android versions prior to 153
Timeline
- 2026-07-21: advisory: Mozilla Foundation Security Advisory 2026-68 published.
- 2026-07-21: patched: Fixed in Firefox 153.