Clickjacking Vulnerability in Mozilla Firefox and Firefox ESR
CVE-2025-5267
5.4MEDIUM
What is CVE-2025-5267?
A clickjacking vulnerability exists in Mozilla Firefox and Firefox ESR, allowing an attacker to potentially manipulate a user interface element to deceive users into unintentionally sending sensitive information, such as saved payment card details, to a malicious site. This security flaw affects versions of Firefox below 139 and Firefox ESR below 128.11, making it crucial for users to update their browsers to mitigate the risk of exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Firefox < 139
Firefox ESR < 128.11
Thunderbird < 139
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ameen Basha M K