Improper Restriction of Rendered UI Layers or Frames in Firefox for Android and Mozilla Firefox - CVE-2026-16397
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform clickjacking attacks.
The vulnerability exists due to improper user interface control in the WebExtensions component when rendering extension user interface elements. A remote attacker can present crafted interface elements to perform clickjacking attacks.
This issue is specific to Firefox for Android.
Affected software
Mozilla Firefox
How to mitigate CVE-2026-16397
Mozilla Firefox - update to 153.0