Improper Restriction of Rendered UI Layers or Frames in Mozilla products - CVE-2026-84139

 

Improper Restriction of Rendered UI Layers or Frames in Mozilla products - CVE-2026-84139

Published: September 1, 2026


Vulnerability identifier: #VU146622
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84139
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform clickjacking attacks.

The vulnerability exists due to improper UI protection in the DOM: Events component when rendering crafted web content. A remote attacker can present crafted content to perform clickjacking attacks.

User interaction is required to interact with crafted content.


Affected software

Firefox for Android
Mozilla Firefox
Firefox ESR

How to mitigate CVE-2026-84139

Install security update from vendor's website.

Firefox for Android - update to 155.0
Mozilla Firefox - update to 155.0
Firefox ESR - update to 153.2.0

External References

Related Security Bulletins