← Vulnerability feed

Vulnerability record · CVE-2026-74975 · published 18 August 2026

CVE-2026-74975: Mozilla firefox mobile vulnerability

Mozilla · Firefox Mobile

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

5.4 CVSS 3.1 Medium EPSS 0.25% · top 85.7% CWE-451 · CWE-451
5.4CVSS 3.1 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
25 Aug 2026Last modified by NVD

Description

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-74975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2022-26486Firefox WebGPU IPC use-after-free enables sandbox escapeAn unexpected message in the WebGPU IPC framework triggers a use-after-free in Mozilla Firefox, Firefox ESR, Firefox for Android, Thunderbird and Foc…KEVEPSS 2.3%analysed8.8CVE-2022-26485Firefox XSLT parameter removal use-after-freeRemoving an XSLT parameter during processing in Mozilla Firefox could trigger a use-after-free condition. Mozilla reported attacks in the wild abusin…KEVEPSS 14%analysed10.0CVE-2012-1126Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 5.6%9.8CVE-2026-84135Mozilla firefox mobile improper input validation vulnerabilityOther issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.EPSS 0.45%9.8CVE-2023-49060Mozilla firefox mobile vulnerabilityAn attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulne…EPSS 0.64%9.3CVE-2012-1128Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL…EPSS 4.6%9.3CVE-2012-1129Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 3.8%9.3CVE-2012-1130Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2026-74975), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.