Executive brief
Firefox for Android's download confirmation notification can be displayed on top of content from other websites, allowing attackers to trick users into believing a download prompt is legitimate when it actually originates from a malicious site. An attacker can redirect a user to a legitimate website while keeping the download notification visible, deceiving the user into thinking the notification is from that site rather than the attacker's origin.
Technical details
This is a spoofing vulnerability in the Downloads component of Firefox for Android caused by improper UI overlay handling. The download confirmation notification dialog fails to disappear when the user navigates to a different origin, allowing an attacker to display a download prompt on top of legitimate site content. An attacker can craft a malicious page that initiates a download, then automatically redirects to a popular website (such as Google) while keeping the download notification visible, leading the user to believe the notification originates from the legitimate site. The vulnerability requires user interaction (clicking a link) but no authentication. The issue was fixed in Firefox 154.
Affected products
- Mozilla Firefox for Android before 154
Timeline
- 2026-08-18: disclosed
- 2026: patched: Fixed in Firefox 154