Impact
The vulnerability is a clickjacking flaw in the Widget component that allows a malicious web page to trick a user into interacting with hidden or masked Firefox and Thunderbird UI elements, potentially causing unintended actions such as navigation to malicious sites or execution of configuration changes. This UI deception exploits the user’s intent and the browser’s rendering behavior, providing attackers a path to influence user decisions without requiring elevated privileges.
Affected Systems
Affected by the Mozilla Firefox browser and Thunderbird application, specifically versions before 154 and the ESR 153.1 branch for Firefox and versions before 154 or 153.1 for Thunderbird, which did not contain the widget component’s built‑in anti‑clickjacking protections. Systems running these versions are vulnerable unless they upgrade to the patched releases.
Risk and Exploitability
Because clickjacking is a client‑side technique, the attack vector is typical web‑based; an attacker only needs to host a malicious page and entice a user to visit it. No exploitation of local privileges is required. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating a relatively low but still significant risk, especially in environments with users who may easily fall for UI deception. The CVSS score is 8.1, indicating a high severity, so the potential for unauthorized UI actions warrants immediate remediation.
OpenCVE Enrichment