Junglewise Threat Intelligence

CVE-2026-12322: Mozilla Firefox clickjacking in Widget: Gtk component

CVE-2026-12322 · Severity: info · CVSS 3.3 · Published 2026-06-16

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability in the Firefox web browser could allow a malicious website to trick users into performing unintended actions. By manipulating how the browser handles certain interface elements on Linux-based systems, an attacker could overlay hidden buttons or links over legitimate content. This could lead to unauthorized configuration changes or accidental data disclosure if a user is misled into clicking on the hidden elements.

Technical details

A clickjacking vulnerability exists in the 'Widget: Gtk' component of Mozilla Firefox. The flaw allows a malicious webpage to overlay or disguise user interface elements, potentially leading to UI redress attacks where a user's clicks are hijacked to perform actions on a different, hidden layer. This specific issue affects the Gtk-based implementation, primarily used on Linux distributions. An attacker would need to entice a user to visit a specially crafted website to exploit this vulnerability. The issue is addressed in Firefox version 152.

Affected products

  • Mozilla Firefox < 152

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched

References

Related threats