CVE-2026-12322
published 2026-06-16CVE-2026-12322: Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
PriorityP424medium5.4CVSS 3.1
AVNACLPRNUIRSUCLINAL
EPSS
0.17%
6.0th percentile
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 152 | Firefox 152 |
| mozilla | firefox | < 152.0.0 | 152.0.0 |
| mozilla | thunderbird | < Thunderbird 152 | Thunderbird 152 |
| mozilla | thunderbird | < 152.0.0 | 152.0.0 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: thunderbird: Clickjacking issue in the Widget: Gtk component
vendor_redhat·2026-06-16·CVSS 5.4
CVE-2026-12322 [MEDIUM] CWE-1021 firefox: thunderbird: Clickjacking issue in the Widget: Gtk component
firefox: thunderbird: Clickjacking issue in the Widget: Gtk component
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Clickjacking issue in the Widget: Gtk component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/thunderbird-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat En
Mozilla
Mozilla Foundation Security Advisory 2026-57: CVE-2026-12322
vendor_mozilla·CVSS 5.4
CVE-2026-12322 [MEDIUM] Mozilla Foundation Security Advisory 2026-57: CVE-2026-12322
Mozilla Foundation Security Advisory 2026-57
CVE: CVE-2026-12322
Product: Firefox
Impact: high
Fixed in: Firefox 152
Mozilla
Mozilla Foundation Security Advisory 2026-60: CVE-2026-12322
vendor_mozilla·CVSS 5.4
CVE-2026-12322 [MEDIUM] Mozilla Foundation Security Advisory 2026-60: CVE-2026-12322
Mozilla Foundation Security Advisory 2026-60
CVE: CVE-2026-12322
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 152
VulDB
Mozilla Firefox up to 151 Gtk clickjacking (Nessus ID 321405 / WID-SEC-2026-1959)
vuldb·2026-07-10·CVSS 5.4
CVE-2026-12322 [MEDIUM] Mozilla Firefox up to 151 Gtk clickjacking (Nessus ID 321405 / WID-SEC-2026-1959)
A vulnerability was found in Mozilla Firefox up to 151. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Gtk. The manipulation leads to clickjacking.
This vulnerability is uniquely identified as CVE-2026-12322. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
Clickjacking issue in the Widget: Gtk component.
ghsa_unreviewed·2026-06-16
CVE-2026-12322 [MEDIUM] CWE-1021 Clickjacking issue in the Widget: Gtk component.
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152.
No detection rules found.
No public exploits indexed.
2026-06-16
Published