Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-74980

CVE-2026-74980: Firefox for Android Clickjacking Vulnerability

CVE-2026-74980 is a clickjacking vulnerability affecting the Downloads component in Firefox for Android that allows attackers to trick users into unintended actions. This article covers technical details, affected versions, impact, and mitigation steps.

Updated:

CVE-2026-74980 Overview

CVE-2026-74980 is a clickjacking vulnerability in the Downloads component of Firefox for Android. The flaw allows attackers to trick users into interacting with hidden or disguised interface elements within the Downloads UI. Mozilla addressed the issue in Firefox 154. The weakness is categorized under CWE-1021: Improper Restriction of Rendered UI Layers or Frames.

Critical Impact

An attacker who successfully lures a user to a malicious page can manipulate the Downloads component to trigger unintended actions, compromising the integrity of file operations on the device.

Affected Products

  • Mozilla Firefox for Android (versions prior to 154)
  • Downloads component in Firefox for Android
  • Android platform installations of Firefox

Discovery Timeline

  • 2026-08-18 - CVE-2026-74980 published to NVD
  • 2026-08-20 - Last updated in NVD database
  • Firefox 154 - Mozilla releases fixed version addressing the vulnerability

Technical Details for CVE-2026-74980

Vulnerability Analysis

The vulnerability resides in the Downloads component of Firefox for Android. Clickjacking occurs when an attacker overlays or disguises UI elements so a user's tap performs an action different from what appears on screen. In this case, the Downloads component fails to properly restrict how its interface layers can be rendered or interacted with. A malicious web page can leverage this weakness to induce a user to approve, open, or manipulate downloaded content without informed consent.

Because the attack requires user interaction and targets integrity rather than confidentiality, exploitation depends on social engineering to bring the victim to attacker-controlled content. Once loaded, the malicious page can drive taps toward hidden Downloads actions.

Root Cause

The root cause is improper restriction of rendered UI layers in the Downloads component (CWE-1021). The component does not enforce sufficient safeguards against overlay or framing techniques that obscure the true target of a user tap. Detailed fix information is available in the Mozilla Bug Report #2049034 and Mozilla Security Advisory MFSA-2026-74.

Attack Vector

Attackers deliver the exploit over the network by hosting a crafted web page and enticing the victim to visit it in Firefox for Android. The page manipulates the rendering of Downloads-related UI so user taps land on hidden controls. Successful exploitation requires the victim to interact with the deceptive interface. No authentication is required. Refer to the Mozilla Security Advisory MFSA-2026-74 for vendor technical details.

Detection Methods for CVE-2026-74980

Indicators of Compromise

  • Unexpected files present in the device's Downloads directory that the user does not recall initiating.
  • Firefox for Android running a version prior to 154 while browsing untrusted content.
  • Web sessions that render overlays, transparent iframes, or covering UI elements near download prompts.

Detection Strategies

  • Inventory mobile endpoints to identify installations of Firefox for Android below version 154.
  • Inspect mobile web traffic for pages using framing, opacity tricks, or CSS transforms that could overlay browser UI.
  • Correlate download events on managed Android devices with the originating web domain to spot suspicious patterns.

Monitoring Recommendations

  • Monitor Firefox for Android version telemetry across the mobile fleet through mobile device management (MDM) tooling.
  • Track access to newly registered or low-reputation domains from managed Android browsers.
  • Alert on repeated download events initiated within short time windows from a single web origin.

How to Mitigate CVE-2026-74980

Immediate Actions Required

  • Upgrade Firefox for Android to version 154 or later on all managed and personal devices.
  • Push the update through mobile device management platforms and Google Play managed configurations where available.
  • Communicate to users the importance of restarting the browser after the update to ensure the patched Downloads component loads.

Patch Information

Mozilla fixed CVE-2026-74980 in Firefox 154. Users and administrators should install this release or a later version. Full advisory details are available in Mozilla Security Advisory MFSA-2026-74 and the Mozilla Bug Report #2049034.

Workarounds

  • Restrict browsing to trusted domains until the Firefox for Android update is applied.
  • Advise users to carefully review download prompts and cancel any unexpected file save requests.
  • Consider using an alternative browser configuration or enterprise browser policy that limits exposure to untrusted web content on Android.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.