Description
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Firefox’s DOM Events component allows an attacker to perform clickjacking by overlaying a malicious page over a legitimate user interface. This can trick users into clicking hidden or disguised elements, potentially triggering unintended actions. The vulnerability does not grant direct code execution or remote access, but can enable social engineering attacks that compromise user intent.

Affected Systems

The issue affects Mozilla Firefox releases older than version 155 and Firefox ESR older than 153.2. Only these vulnerable builds are impacted; newer releases contain the fix.

Risk and Exploitability

Clickjacking remains a low‑to‑moderate risk because it relies on a user interacting with a compromised webpage. The EPSS score is unavailable and it is not listed in the CISA KEV catalog, suggesting limited reports of exploitation. Still, the lack of a defensive mechanism in affected browsers makes the attack vector client‑side and potentially achievable through malicious sites or phishing. System administrators should treat the vulnerability as a priority for patching.

Generated by OpenCVE AI on September 1, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 155 or later (or ESR 153.2 or later) to resolve the clickjacking flaw.
  • Synchronize all client installations of Firefox with the latest updated releases to ensure the patch is applied consistently.
  • Monitor user activity for anomalous click patterns or report suspicious clicks, and consider disabling or restricting frame embedding through browser settings as an additional precaution.

Generated by OpenCVE AI on September 1, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-620

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Clickjacking issue in the DOM: Events component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:19:05.943Z

Reserved: 2026-09-01T07:25:54.254Z

Link: CVE-2026-84139

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:08.023

Modified: 2026-09-01T13:20:08.023

Link: CVE-2026-84139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:03Z

Weaknesses
  • CWE-620

    Unverified Password Change