Junglewise Threat Intelligence

CVE-2026-74980: Mozilla Firefox for Android clickjacking in Downloads component

CVE-2026-74980 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Executive brief

Firefox for Android's Downloads component is vulnerable to clickjacking attacks, where a malicious website can trick users into performing unintended actions on download prompts. An attacker could overlay transparent frames to deceive users into authorizing downloads or taking other actions without their knowledge, potentially leading to unwanted file installation or data exposure.

Technical details

This is a clickjacking vulnerability in the Downloads component of Firefox for Android. The vulnerability stems from insufficient UI protection against clickjacking attacks, where transparent overlays can be layered on top of download dialogs to trick users into clicking on interface elements they believe they are interacting with. The attack is network-based and requires user interaction (visiting a malicious website). An attacker can deceive users into authorizing downloads or performing unintended actions. Firefox patched this vulnerability in version 154, released in August 2026.

Affected products

  • Mozilla Firefox for Android before 154

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in Firefox 154

References

Related threats