Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox for Android - CVE-2026-74980

 

Improper Restriction of Rendered UI Layers or Frames in Mozilla Firefox and Firefox for Android - CVE-2026-74980

Published: August 18, 2026


Vulnerability identifier: #VU144101
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74980
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform clickjacking.

The vulnerability exists due to improper UI protection in the Downloads component when displaying download information. A remote attacker can present crafted content to perform clickjacking.


Affected software

Mozilla Firefox
Firefox for Android
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Desktop Applications Module
MozillaFirefox-translations-common
MozillaFirefox-debugsource
MozillaFirefox-debuginfo
MozillaFirefox
MozillaFirefox-devel
MozillaFirefox-translations-other

How to mitigate CVE-2026-74980

Install security update from vendor's website.

Mozilla Firefox - update to 154.0
Firefox for Android - update to 154.0
MozillaFirefox-translations-common - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-debugsource - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-debuginfo - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-devel - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-translations-other - update to 140.14.0-150200.152.251.1

External References

Related Security Bulletins