Impact
The vulnerability is a clickjacking flaw in the DOM Events component, identified as CWE‑1021. It allows an attacker to overlay a deceptive interface over genuine web content, tricking users into interacting with hidden or manipulated controls. This type of UI redress can facilitate social‑engineering attacks but, according to the description, does not grant code execution or remote access capabilities.
Affected Systems
Mozilla Firefox versions older than 155, and Firefox ESR older than 153.2, are affected. The same applies to Thunderbird releases older than 155 and Thunderbird ESR older than 153.2; all later releases contain the fix.
Risk and Exploitability
The CVSS score of 9.8 indicates a high‑severity issue that can be leveraged through social engineering. Exploitation normally requires a user to visit a malicious web page that embeds or frames target content and induce a click on a concealed element. The EPSS score of <1% and the absence from the CISA KEV catalog suggest that active exploitation may be limited, yet the potential for widespread attacks underscores the need for prompt patching.
OpenCVE Enrichment