Description
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw allows a malicious user to overlay a transparent or hidden WebExtensions component in Firefox for Android, causing a user to unknowingly activate unwanted actions or submit sensitive data to a different site. The vulnerability is categorized as CWE‑1021, indicating improper handling of UI elements that can be tricked into presenting alternate interfaces. Once exploited, an attacker could execute arbitrary web‑based actions or phishing attacks without the user’s awareness, compromising the integrity of the user’s interactions and potentially leading to credential compromise or other downstream attacks.

Affected Systems

The issue is specific to the Firefox for Android product from Mozilla. Only versions prior to 153 contain the flaw; Firefox 153 and later include the patch that prevents malicious click manipulation in the WebExtensions component.

Risk and Exploitability

The CVSS score of 6.5 places the vulnerability in the medium‑severity range, but the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the current time. Because the vulnerability is not listed in CISA’s KEV catalogue, there is no known widespread use in the open‑world. An attacker would still need to lure a victim onto a page that renders a WebExtensions component that can be tricked, making the attack vector likely to be phishing or malicious web content. In the absence of an automated exploit, manual user interaction remains the primary prerequisite.

Generated by OpenCVE AI on July 30, 2026 at 17:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 153 or later for Android to eliminate the clickjacking flaw
  • Remove or disable any untrusted or custom add‑ons that load WebExtensions
  • Make sure the "Allow undistributed extensions" setting is turned off in the browser preferences

Generated by OpenCVE AI on July 30, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Title Clickjacking issue in the WebExtensions component in Firefox for Android
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-21T19:29:51.336Z

Reserved: 2026-07-20T21:57:25.987Z

Link: CVE-2026-16397

cve-icon Vulnrichment

Updated: 2026-07-21T19:28:58.549Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:14.977

Modified: 2026-07-22T18:29:21.307

Link: CVE-2026-16397

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:10Z

Links: CVE-2026-16397 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:45:03Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames