CVE-2026-8961
Description
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Spoofing vulnerability in Firefox and Thunderbird's Form Autofill component could allow an attacker to manipulate autofill data, fixed in Firefox 151, ESR 140.11, and Thunderbird 151/140.11.
Vulnerability
A spoofing issue exists in the Form Autofill component of Firefox and Thunderbird [1][2][3][4]. This vulnerability allows an attacker to spoof autofill data, potentially tricking users into entering sensitive information into unintended fields. The issue is present in Firefox versions prior to 151, Firefox ESR prior to 140.11, and Thunderbird versions prior to 151 and 140.11 [1][2][3][4].
Exploitation
An attacker could craft a malicious website or email (in Thunderbird, scripting is disabled in email, but the flaw could be exploited in browser-like contexts [2][3]) to inject spoofed autofill entries. The attacker would need to convince the user to interact with the malicious content, such as clicking on a form field, to trigger the spoofing.
Impact
Successful exploitation could lead to the autofill component suggesting fraudulent data, potentially causing the user to submit sensitive information (e.g., credentials, personal details) to an attacker-controlled destination. This could result in information disclosure and credential theft.
Mitigation
The issue is fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11, all released on May 19, 2026 [1][2][3][4]. Users should update to these versions or later. No workarounds are available; updating is the recommended mitigation.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <151,<140.11
- Range: <151
- Range: <151
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.mozilla.org/security/advisories/mfsa2026-46/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-48/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-50/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-51/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.