Clickjacking Vulnerability in Mozilla Firefox and Firefox ESR
CVE-2025-5267

5.4MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
27 May 2025

What is CVE-2025-5267?

A clickjacking vulnerability exists in Mozilla Firefox and Firefox ESR, allowing an attacker to potentially manipulate a user interface element to deceive users into unintentionally sending sensitive information, such as saved payment card details, to a malicious site. This security flaw affects versions of Firefox below 139 and Firefox ESR below 128.11, making it crucial for users to update their browsers to mitigate the risk of exploitation.

Affected Version(s)

Firefox < 139

Firefox ESR < 128.11

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ameen Basha M K
.
The Cyber Security Vulnerability Database.