Junglewise Threat Intelligence

CVE-2026-74951: Mozilla Firefox clickjacking in Android

CVE-2026-74951 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Mozilla Firefox Mobile, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox for Android is vulnerable to a clickjacking attack that could trick users into performing unintended actions, such as granting permissions or triggering unintended downloads. An attacker could overlay a malicious webpage on top of legitimate content to deceive users into clicking on hidden interface elements, potentially compromising the user's device or data.

Technical details

CVE-2026-74951 is a clickjacking vulnerability in Firefox for Android. The vulnerability stems from insufficient protection against UI redressing attacks where an attacker can overlay transparent or disguised malicious content over legitimate webpage elements. The attack requires network access and user interaction (the user must be tricked into clicking). An attacker can leverage this to hijack user actions such as permission grants, file downloads, or navigation to malicious sites. Mozilla fixed this vulnerability in Firefox 154, released on 2026-08-18.

Affected products

  • Mozilla Firefox before 154

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in Firefox 154

References

Related threats