Clickjacking Vulnerability in Firefox for Android WebExtensions
CVE-2026-16397

6.5MEDIUM

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-16397?

A clickjacking vulnerability exists in the WebExtensions component of Firefox for Android, which could allow an attacker to trick users into clicking on hidden or disguised elements. This could lead to unauthorized actions being performed on behalf of the user without their consent. Mozilla has addressed this issue in Firefox version 153, reinforcing user protection against such deceptive security threats.

Affected Version(s)

Firefox 153

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hafiizh
.