Junglewise Threat Intelligence

CVE-2026-74975: Mozilla Firefox for Android spoofing in Downloads component

CVE-2026-74975 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Executive brief

Firefox for Android's download confirmation notification can be displayed on top of content from other websites, allowing attackers to trick users into believing a download prompt is legitimate when it actually originates from a malicious site. An attacker can redirect a user to a legitimate website while keeping the download notification visible, deceiving the user into thinking the notification is from that site rather than the attacker's origin.

Technical details

This is a spoofing vulnerability in the Downloads component of Firefox for Android caused by improper UI overlay handling. The download confirmation notification dialog fails to disappear when the user navigates to a different origin, allowing an attacker to display a download prompt on top of legitimate site content. An attacker can craft a malicious page that initiates a download, then automatically redirects to a popular website (such as Google) while keeping the download notification visible, leading the user to believe the notification originates from the legitimate site. The vulnerability requires user interaction (clicking a link) but no authentication. The issue was fixed in Firefox 154.

Affected products

  • Mozilla Firefox for Android before 154

Timeline

  • 2026-08-18: disclosed
  • 2026: patched: Fixed in Firefox 154

References

Related threats