Executive brief
A vulnerability in the Firefox web browser could allow a malicious website to trick users into performing unintended actions. By manipulating how the browser handles certain interface elements on Linux-based systems, an attacker could overlay hidden buttons or links over legitimate content. This could lead to unauthorized configuration changes or accidental data disclosure if a user is misled into clicking on the hidden elements.
Technical details
A clickjacking vulnerability exists in the 'Widget: Gtk' component of Mozilla Firefox. The flaw allows a malicious webpage to overlay or disguise user interface elements, potentially leading to UI redress attacks where a user's clicks are hijacked to perform actions on a different, hidden layer. This specific issue affects the Gtk-based implementation, primarily used on Linux distributions. An attacker would need to entice a user to visit a specially crafted website to exploit this vulnerability. The issue is addressed in Firefox version 152.
Affected products
- Mozilla Firefox < 152
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched