Improper Restriction of Rendered UI Layers or Frames in Mozilla products - CVE-2026-84139
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform clickjacking attacks.
The vulnerability exists due to improper UI protection in the DOM: Events component when rendering crafted web content. A remote attacker can present crafted content to perform clickjacking attacks.
User interaction is required to interact with crafted content.
Affected software
Mozilla Firefox
Firefox ESR
How to mitigate CVE-2026-84139
Mozilla Firefox - update to 155.0
Firefox ESR - update to 153.2.0