Description
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a clickjacking flaw in the Widget component that allows a malicious web page to trick a user into interacting with hidden or masked Firefox and Thunderbird UI elements, potentially causing unintended actions such as navigation to malicious sites or execution of configuration changes. This UI deception exploits the user’s intent and the browser’s rendering behavior, providing attackers a path to influence user decisions without requiring elevated privileges.

Affected Systems

Affected by the Mozilla Firefox browser and Thunderbird application, specifically versions before 154 and the ESR 153.1 branch for Firefox and versions before 154 or 153.1 for Thunderbird, which did not contain the widget component’s built‑in anti‑clickjacking protections. Systems running these versions are vulnerable unless they upgrade to the patched releases.

Risk and Exploitability

Because clickjacking is a client‑side technique, the attack vector is typical web‑based; an attacker only needs to host a malicious page and entice a user to visit it. No exploitation of local privileges is required. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating a relatively low but still significant risk, especially in environments with users who may easily fall for UI deception. The CVSS score is 8.1, indicating a high severity, so the potential for unauthorized UI actions warrants immediate remediation.

Generated by OpenCVE AI on August 21, 2026 at 17:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Firefox or Thunderbird update to their respective patched releases (Firefox 154/ESR 153.1 or Thunderbird 154/153.1) to obtain the patched Widget component.
  • Configure browser settings to disable or restrict the Widget component when it is not required, reducing the attack surface for clickjacking.
  • If possible, deploy browser extensions that enforce clickjacking protection or reinforce Content Security Policy headers as an additional buffer until the patch is in place.

Generated by OpenCVE AI on August 21, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Fri, 21 Aug 2026 00:15:00 +0000


Tue, 18 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1028

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-1028
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Clickjacking issue in the Widget component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T18:57:59.710Z

Reserved: 2026-08-17T11:59:02.002Z

Link: CVE-2026-74978

cve-icon Vulnrichment

Updated: 2026-08-18T18:56:50.664Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:36.390

Modified: 2026-08-25T16:09:42.393

Link: CVE-2026-74978

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-18T12:23:39Z

Links: CVE-2026-74978 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:15:05Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames