Executive brief
Firefox for Android's Downloads component is vulnerable to clickjacking attacks, where a malicious website can trick users into performing unintended actions on download prompts. An attacker could overlay transparent frames to deceive users into authorizing downloads or taking other actions without their knowledge, potentially leading to unwanted file installation or data exposure.
Technical details
This is a clickjacking vulnerability in the Downloads component of Firefox for Android. The vulnerability stems from insufficient UI protection against clickjacking attacks, where transparent overlays can be layered on top of download dialogs to trick users into clicking on interface elements they believe they are interacting with. The attack is network-based and requires user interaction (visiting a malicious website). An attacker can deceive users into authorizing downloads or performing unintended actions. Firefox patched this vulnerability in version 154, released in August 2026.
Affected products
- Mozilla Firefox for Android before 154
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154