Executive brief
A spoofing vulnerability exists in the toolbar component of Firefox for Android. This flaw could allow a malicious website to misrepresent its identity or display misleading information in the browser's address bar area. An attacker could use this to trick users into providing sensitive information on a fraudulent site that appears legitimate.
Technical details
A spoofing vulnerability was identified in the Toolbar component of Firefox for Android. The flaw allows for the potential manipulation of the browser's user interface elements, specifically the address bar or toolbar area, to display incorrect origin information. While specific technical details regarding the root cause are restricted in the associated bug report, the impact is classified as 'moderate' by Mozilla. An attacker could leverage this to conduct phishing attacks by making a malicious site appear as a trusted domain. The vulnerability is addressed in Firefox for Android version 151.
Affected products
- Mozilla Firefox for Android < 151
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-05-19: patched