Spoofing Vulnerability in Firefox Affects Multiple Versions
CVE-2026-0890

5.4MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
13 January 2026

What is CVE-2026-0890?

A spoofing vulnerability has been identified in the DOM functionalities related to Copy & Paste and Drag & Drop components in Firefox. This issue allows malicious actors to manipulate users’ interactions through deceptive means when using affected versions of the browser. Specifically, this impacts Firefox versions prior to 147 and Firefox ESR versions prior to 140.7. Users are advised to update their browsers to the latest versions to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Firefox < 147

Firefox ESR < 140.7

Thunderbird < 147

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edgar Chen
.