Junglewise Threat Intelligence

CVE-2026-8960: Mozilla Firefox spoofing in WebExtensions

CVE-2026-8960 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A spoofing vulnerability was identified in the WebExtensions component of the Firefox web browser. This flaw could allow a malicious extension or website to misrepresent information to the user, potentially leading to phishing or other deceptive activities. Users are advised to update to Firefox 151 or later to resolve this issue.

Technical details

A spoofing vulnerability exists in the WebExtensions component of Mozilla Firefox. While specific technical details are restricted in the associated bug report (Bug 1940116), the flaw allows for the misrepresentation of UI elements or data handled by browser extensions. An attacker could potentially leverage this to perform phishing attacks or deceive users about the origin or nature of web content. The vulnerability is resolved in Firefox 151.

Affected products

  • Mozilla Firefox < 151

Timeline

  • 2026-05-19: advisory: Mozilla Foundation Security Advisory 2026-46 published.
  • 2026-05-19: patched: Fixed in Firefox 151.

References

Related threats