Impact
This flaw allows a malicious user to overlay a transparent or hidden WebExtensions component in Firefox for Android, causing a user to unknowingly activate unwanted actions or submit sensitive data to a different site. The vulnerability is categorized as CWE‑1021, indicating improper handling of UI elements that can be tricked into presenting alternate interfaces. Once exploited, an attacker could execute arbitrary web‑based actions or phishing attacks without the user’s awareness, compromising the integrity of the user’s interactions and potentially leading to credential compromise or other downstream attacks.
Affected Systems
The issue is specific to the Firefox for Android product from Mozilla. Only versions prior to 153 contain the flaw; Firefox 153 and later include the patch that prevents malicious click manipulation in the WebExtensions component.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium‑severity range, but the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the current time. Because the vulnerability is not listed in CISA’s KEV catalogue, there is no known widespread use in the open‑world. An attacker would still need to lure a victim onto a page that renders a WebExtensions component that can be tricked, making the attack vector likely to be phishing or malicious web content. In the absence of an automated exploit, manual user interaction remains the primary prerequisite.
OpenCVE Enrichment