Junglewise Threat Intelligence

CVE-2026-84139: Mozilla Firefox clickjacking issue in DOM Events

CVE-2026-84139 · Severity: medium · CVSS 6.1 · Published 2026-09-01

Executive brief

Firefox's DOM Events component contained a clickjacking vulnerability that could allow a malicious website to trick users into unintended actions by overlaying interface elements. An attacker could exploit this to manipulate user interactions without their knowledge, potentially leading to unauthorized actions or data exposure. This vulnerability affected Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR across multiple versions until September 2026.

Technical details

A clickjacking issue in the DOM: Events component allowed attackers to disguise the true target of user clicks through UI element manipulation. The vulnerability was present in Firefox prior to version 155, Firefox ESR prior to 153.2, Thunderbird prior to 155, and Thunderbird ESR prior to 153.2. It could be exploited via network vector without requiring authentication or special privileges. An attacker could craft a malicious web page to trick users into performing unintended actions, such as granting permissions or triggering dangerous operations. Mozilla patched the vulnerability in the September 2026 security update.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 155
  • Mozilla Thunderbird ESR before 153.2

Timeline

  • 2026-09-01: disclosed: Disclosed in Mozilla Security Advisory MFSA2026-82
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird ESR 153.2

References

Related threats