Spoofing attack in Firefox for Android and Mozilla Firefox - CVE-2026-8951
Published: May 19, 2026
Vulnerability identifier: #VU131852
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8951
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to spoof browser interface elements.
The vulnerability exists due to improper UI representation in the Toolbar component when rendering interface content. A remote attacker can present crafted content to spoof browser interface elements.
This issue is specific to Firefox for Android.
Affected software
Firefox for Android
Mozilla Firefox
Mozilla Firefox
How to mitigate CVE-2026-8951
Install security update from vendor's website.
Firefox for Android - update to 151.0
Mozilla Firefox - update to 151.0
Mozilla Firefox - update to 151.0