VORANT. Threat Intelligence Sign in Get the full feed

Firefox for Android patches data leak flaw

medium vulnerability

A confidentiality vulnerability in Firefox for Android before 153.0.3 could let an attacker access sensitive data; update now.

ANSSI (CERT-FR) published an advisory referencing Mozilla's security bulletin MFSA2026-73, disclosing a vulnerability affecting Firefox for Android versions prior to 153.0.3. The flaw, tracked as CVE-2026-18809, is described as impacting confidentiality of data, meaning an attacker could exploit it to gain unauthorized access to information handled by the browser.

No evidence of active exploitation is provided in the advisory. Mozilla has released a fixed version (153.0.3) and users/administrators are advised to update via the official security bulletin. This is a routine vendor patch disclosure rather than an active threat campaign.

Mentioned in this report

Vulnerabilities CVE-2026-18809

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0971

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free