Executive brief
A security flaw in the Firefox web browser's popup blocker could allow a malicious website to spoof or misrepresent content to the user. This could be used in phishing attacks to trick users into believing they are interacting with a legitimate site or notification. Users should update to Firefox 151 or later to resolve this issue.
Technical details
A spoofing vulnerability was identified in the Popup Blocker component of Mozilla Firefox. The flaw allows for the potential bypass of UI protections, enabling an attacker to present deceptive information to the user. While specific technical root causes are restricted in the associated bug report, the vulnerability is classified as a spoofing issue that can be triggered via web content. The vulnerability is resolved in Firefox version 151.
Affected products
- Mozilla Firefox < 151
Timeline
- 2026-05-19: advisory: Mozilla Foundation Security Advisory 2026-46 published.
- 2026-05-19: patched: Fixed in Firefox 151.