CVE-2026-12323: DOM Spoofing in Firefox and Thunderbird 152
A spoofing vulnerability exists in Firefox and Thunderbird's DOM (Document Object Model) and HTML processing component. An attacker could potentially deceive users about the true origin or content of a webpage or email through DOM manipulation. The issue requires user interaction to trigger and affects confidentiality and availability rather than integrity. Mozilla fixed this in Firefox 152 and Thunderbird 152.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.4 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
- Weaknesses (CWE)
- CWE-1021
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-17
NVD description (verbatim)
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12323 is a DOM and HTML component spoofing issue (CWE-1021: Improper Restriction of Rendered UI Layers or Frames) in Mozilla products. The vulnerability has a CVSS 3.1 score of 5.4 (MEDIUM severity) with a network attack vector, low attack complexity, no privilege requirements, and user interaction required. The attack does not cross security boundaries (Scope: Unchanged) but impacts confidentiality and availability. The root cause involves insufficient controls over how the DOM renders or displays content, potentially allowing an attacker to spoof security indicators, origins, or legitimate content through crafted HTML or JavaScript.
Business impact
Organizations relying on Firefox or Thunderbird for email and browsing face a moderate risk of user deception attacks. An attacker could craft malicious pages or emails that spoof trusted sites or hide malicious content beneath legitimate-looking interfaces, leading to credential harvesting, social engineering, or information disclosure. Since exploitation requires user interaction, the impact is contained to individual sessions; however, widespread browser deployments mean many users could be targeted simultaneously. The vulnerability does not enable remote code execution or system compromise.
Affected systems
Mozilla Firefox versions prior to 152 and Mozilla Thunderbird versions prior to 152 are vulnerable. All platforms running these versions (Windows, macOS, Linux) are in scope. Organizations should audit deployment of Firefox and Thunderbird versions across endpoints to identify exposure. Extended support release (ESR) versions and enterprise deployments should be cross-referenced with Mozilla's official patch timeline.
Exploitability
Exploitation requires user interaction—specifically, a user must visit a malicious webpage or open a crafted email message. No authentication or special privileges are needed on the attacker side, and network access is sufficient. The attack complexity is low. However, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date, indicating no confirmed in-the-wild exploitation or proof-of-concept demonstrating active abuse at this time.
Remediation
Update Firefox to version 152 or later and Thunderbird to version 152 or later immediately. Mozilla released patches on or around the publication date (June 2026). Organizations should prioritize deployment via automated patch management tools and verify successful remediation through version checks. Extended support releases (ESR) may have separate patch timelines; verify against Mozilla's official security advisories for ESR-specific guidance.
Patch guidance
Apply Mozilla's official security updates without delay. Firefox 152 and Thunderbird 152 contain the fix. For enterprise deployments, use automated software distribution systems to push updates across the estate. For ESR-based deployments, consult Mozilla's ESR security advisory to confirm the patched ESR version. Test patches in a staging environment first if possible, though the risk of regression is low for stability-focused security patches. Verify post-patch that no legacy add-ons or configurations break due to DOM-related changes, though this is unlikely.
Detection guidance
Monitor endpoint telemetry for Firefox and Thunderbird version information to identify unpatched systems. Hunting should focus on: (1) users accessing or reporting suspicious phishing attempts via email with unusual origin spoofing or UI anomalies; (2) browser history or email logs showing access to known-malicious craft-and-spoof domains; (3) DOM manipulation or JavaScript execution within high-risk contexts (e.g., login pages, financial sites). No malware signatures or network IOCs are applicable since the vulnerability is client-side and exploitation leaves minimal forensic traces. Log user reports of
Why prioritize this
MEDIUM severity with user-interaction requirement and no KEV inclusion limits urgency, but widespread Firefox and Thunderbird deployments and the confidentiality/availability impact warrant expedited patching. Organizations should complete rollout within 30 days. Prioritize updates for users in high-risk roles (finance, admin, executive) and publicly-facing support staff more likely to receive targeted phishing.
Risk score, explained
The CVSS 3.1 score of 5.4 (MEDIUM) reflects a network-accessible attack with low complexity but mandatory user interaction (reducing severity below 7.0). Confidentiality and Availability impacts are present, but Integrity and System Impact are absent. No privilege escalation or cross-boundary attacks are possible. The lack of KEV listing and absence of reported in-the-wild exploitation further support a moderate rather than critical risk posture, though widespread user base and spoofing nature warrant proactive attention.
Frequently asked questions
Can this vulnerability be exploited without user interaction?
No. The vulnerability requires a user to open a malicious webpage or email message. An attacker cannot exploit this remotely by forcing a connection; the user must actively engage with the spoofed content.
Does this vulnerability allow code execution or system compromise?
No. The vulnerability is limited to spoofing and does not enable remote code execution, privilege escalation, or unauthorized system access. It can lead to user deception and information disclosure, but not malware infection or system takeover.
Is this vulnerability currently being exploited in the wild?
As of the publication date, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. No confirmed in-the-wild exploitation or weaponized proof-of-concept has been publicly disclosed, though organizations should patch proactively nonetheless.
How quickly should we patch this?
Aim to deploy Firefox 152 and Thunderbird 152 across your organization within 30 days. Prioritize high-risk user segments (finance, administration, executives) and conduct testing in staging environments first, though the risk of regression is low for stability-focused security patches.
This analysis is based on publicly available information current as of June 2026. Patch versions, KEV status, and exploit availability are subject to change; verify all remediation guidance against Mozilla's official security advisories before deployment. SEC.co assumes no liability for losses arising from reliance on this intelligence. Organizations are responsible for assessing their own risk and implementing appropriate mitigations based on their environment and threat landscape. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12322MEDIUMClickjacking in Firefox & Thunderbird Gtk Widget Component
- CVE-2026-0061MEDIUMAndroid WindowState Tapjacking Vulnerability – Permission Escalation Risk
- CVE-2026-10733MEDIUMGitLab CI/CD Catalog DoS Vulnerability – Patch Guidance
- CVE-2026-0036HIGHAndroid StageCoordinator Tapjacking Privilege Escalation (CVSS 7.8 HIGH)
- CVE-2026-12348HIGHArc Search Android Address Bar Spoofing Vulnerability
- CVE-2026-28577HIGHAndroid WindowManagerService Tapjacking Vulnerability – Local Privilege Escalation
- CVE-2026-10702MEDIUMFirefox JIT Compiler Miscompilation DoS Vulnerability
- CVE-2026-12298MEDIUMMemory Safety Vulnerability in Firefox and Thunderbird