Spoofing Vulnerability in Firefox Address Bar Component
CVE-2026-16403

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
21 July 2026

What is CVE-2026-16403?

A spoofing vulnerability was identified in the Address Bar component of Firefox, allowing attackers to potentially mislead users into thinking they are visiting a legitimate website. This issue could compromise user trust and secure browsing practices. Mozilla has addressed this flaw in Firefox version 153, enhancing user protection against such deceptive tactics.

Affected Version(s)

Firefox 153

Thunderbird 153

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Renwa
.