Impact
A flaw in Firefox’s DOM Events component allows an attacker to perform clickjacking by overlaying a malicious page over a legitimate user interface. This can trick users into clicking hidden or disguised elements, potentially triggering unintended actions. The vulnerability does not grant direct code execution or remote access, but can enable social engineering attacks that compromise user intent.
Affected Systems
The issue affects Mozilla Firefox releases older than version 155 and Firefox ESR older than 153.2. Only these vulnerable builds are impacted; newer releases contain the fix.
Risk and Exploitability
Clickjacking remains a low‑to‑moderate risk because it relies on a user interacting with a compromised webpage. The EPSS score is unavailable and it is not listed in the CISA KEV catalog, suggesting limited reports of exploitation. Still, the lack of a defensive mechanism in affected browsers makes the attack vector client‑side and potentially achievable through malicious sites or phishing. System administrators should treat the vulnerability as a priority for patching.
OpenCVE Enrichment