Executive brief
Firefox for Android is vulnerable to a clickjacking attack that could trick users into performing unintended actions, such as granting permissions or triggering unintended downloads. An attacker could overlay a malicious webpage on top of legitimate content to deceive users into clicking on hidden interface elements, potentially compromising the user's device or data.
Technical details
CVE-2026-74951 is a clickjacking vulnerability in Firefox for Android. The vulnerability stems from insufficient protection against UI redressing attacks where an attacker can overlay transparent or disguised malicious content over legitimate webpage elements. The attack requires network access and user interaction (the user must be tricked into clicking). An attacker can leverage this to hijack user actions such as permission grants, file downloads, or navigation to malicious sites. Mozilla fixed this vulnerability in Firefox 154, released on 2026-08-18.
Affected products
- Mozilla Firefox before 154
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154