# Firefox for Android patches data leak flaw

Published: 2026-08-05 · Severity: medium
Canonical: https://vorant.io/reports/77929c10-a39d-5dec-92cf-e0306fbb32a3/firefox-for-android-patches-data-leak-flaw

> A confidentiality vulnerability in Firefox for Android before 153.0.3 could let an attacker access sensitive data; update now.

ANSSI (CERT-FR) published an advisory referencing Mozilla's security bulletin MFSA2026-73, disclosing a vulnerability affecting Firefox for Android versions prior to 153.0.3. The flaw, tracked as CVE-2026-18809, is described as impacting confidentiality of data, meaning an attacker could exploit it to gain unauthorized access to information handled by the browser.

No evidence of active exploitation is provided in the advisory. Mozilla has released a fixed version (153.0.3) and users/administrators are advised to update via the official security bulletin. This is a routine vendor patch disclosure rather than an active threat campaign.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18809

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0971

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/77929c10-a39d-5dec-92cf-e0306fbb32a3/firefox-for-android-patches-data-leak-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
