Clickjacking Vulnerability in Firefox and Firefox ESR
CVE-2026-74978

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74978?

A clickjacking vulnerability was identified in the Widget component of the Firefox browser, which could potentially allow an attacker to trick users into clicking on malicious elements masqueraded as legitimate content. This issue was addressed in Firefox version 154 and Firefox ESR version 153.1, enhancing the protection measures to safeguard users from such attacks.

Affected Version(s)

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hafidzaulia28
.