Junglewise Threat Intelligence

CVE-2026-74978: Mozilla Firefox clickjacking issue in Widget component

CVE-2026-74978 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird browsers contain a clickjacking vulnerability in their Widget component that could allow attackers to trick users into performing unintended actions. An attacker can overlay invisible or deceptive UI elements to hijack user clicks, potentially leading to unauthorized account actions, malware installation, or data exposure. The issue has been patched in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Technical details

CVE-2026-74978 is a clickjacking vulnerability affecting the Widget component in Mozilla Firefox and Thunderbird. The vulnerability allows attackers to overlay or manipulate UI elements in a way that deceives users into clicking on unintended targets. Attack requires network access and user interaction (clicking on a malicious link or visiting a compromised website). Successful exploitation can lead to unauthorized user actions, credential theft, or malware distribution. Patches are available in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird before 153.1 ESR

Timeline

  • 2026-08-18: disclosed: CVE-2026-74978 disclosed and advisory published
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1

References

Related threats