QSearchQSearch

CVE-2026-12322

5.4 MEDIUM

Clickjacking issue in the Widget: Gtk component

Published: 2026-06-16 · Last updated: 2026-06-16

Severity and scoring

CVSS
5.4 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
CWE
CWE-1021

Affected products

VendorProduct
mozillafirefox, thunderbird

Description

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-12330 Incorrect boundary conditions in the Internationalization component (5.4 MEDIUM)
  • CVE-2026-12329 Memory safety bug fixed in Thunderbird ESR 140.12 (5.3 MEDIUM)
  • CVE-2026-12328 Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151 (8.1 HIGH)
  • CVE-2026-12323 Spoofing issue in the DOM: Core & HTML component (5.4 MEDIUM)
  • CVE-2026-12321 JIT miscompilation in the JavaScript: WebAssembly component (5.4 MEDIUM)

Same CWE

  • CVE-2026-12323 Spoofing issue in the DOM: Core & HTML component (5.4 MEDIUM)
  • CVE-2026-10733 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.... (4.3 MEDIUM)
  • CVE-2026-28577 In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack (7.8 HIGH)
  • CVE-2026-0061 In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overla... (5.9 MEDIUM)
  • CVE-2026-0036 In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack (7.8 HIGH)