Impact
The vulnerability allows an attacker to overlay the browser interface through a transparent page so that a user unknowingly clicks a malicious element. This can lead the user to perform unintended actions within Firefox for Android.
Affected Systems
Affected systems include Mozilla Firefox on Android with any build prior to version 154. The descriptive title and reference notes confirm that the flaw specifically impacted the Android rendering of web content.
Risk and Exploitability
Exploitability is straightforward, requiring only a malicious web page visited by a user. EPSS score is not available, and the vulnerability is not listed in CISA KEV; the CVSS score is 6.5. The issue is mitigated entirely by upgrading to Firefox 154 or later, which removes the flaw. Without a patch, attackers can continue to clickjacking the device UI at will.
OpenCVE Enrichment