Spoofing attack in Firefox for Android and Mozilla Firefox - CVE-2026-16404
Published: July 22, 2026
Vulnerability identifier: #VU139021
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16404
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to spoof trusted content.
The vulnerability exists due to improper user interface control in Firefox for Android when displaying content. A remote attacker can present crafted content to spoof trusted content.
This issue is specific to Firefox for Android.
Affected software
Firefox for Android
Mozilla Firefox
Mozilla Firefox
How to mitigate CVE-2026-16404
Install security update from vendor's website.
Firefox for Android - update to 153.0
Mozilla Firefox - update to 153.0
Mozilla Firefox - update to 153.0