Junglewise Threat Intelligence

CVE-2026-8961: Mozilla Firefox spoofing in Form Autofill component

CVE-2026-8961 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A spoofing vulnerability exists in the Form Autofill component of Mozilla Firefox. This component is responsible for automatically populating web forms with saved user information like addresses or credit card details. An exploit could allow a malicious website to misrepresent information or trick users into providing data under false pretenses, potentially leading to phishing or unauthorized data entry.

Technical details

A spoofing vulnerability was identified in the Form Autofill component of Mozilla Firefox and Firefox ESR. The flaw allows for potential UI or data spoofing during the autofill process. While specific root cause details are restricted in the associated Bugzilla report, the vulnerability typically involves a failure to properly validate or display the origin or content of form fields being populated. An attacker would need to entice a user to visit a malicious webpage to trigger the issue. This could result in the user being misled about what data is being submitted or to which origin. The issue is resolved in Firefox 151 and Firefox ESR 140.11.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats