Junglewise Threat Intelligence

CVE-2026-8963: Mozilla Firefox spoofing in Web Speech component

CVE-2026-8963 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A spoofing vulnerability was identified in the Web Speech component of the Firefox web browser. This flaw could allow a malicious website to misrepresent information or mimic legitimate browser interfaces, potentially tricking users into performing unintended actions or disclosing sensitive information. The issue has been resolved in Firefox version 151.

Technical details

A spoofing vulnerability exists in the Web Speech API component of Mozilla Firefox. While specific technical details regarding the root cause are restricted in the associated bug report (Bug 2021222), the flaw allows for the manipulation of browser-presented information, categorized as a spoofing attack. An attacker would likely need to entice a user to visit a specially crafted website to trigger the vulnerability. The impact is limited to user-interface spoofing and does not appear to allow for remote code execution or direct data exfiltration. The vulnerability is addressed in Firefox 151.

Affected products

  • Mozilla Firefox < 151

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats