Mozilla Foundation Security Advisory 2015-35

Cursor clickjacking with flash and images

Announced
March 31, 2015
Reporter
Jordi Chancel
Impact
Moderate
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 37
  • SeaMonkey 2.35

Description

Security researcher Jordi Chancel reported a mechanism that made cursor invisible through flash content and then replaced it through the layering of HTML content. This flaw can be in used in combination with an image of the cursor manipulated through JavaScript, leading to clickjacking during subsequent interactions with HTML content.

This flaw only affects OS X systems. Windows and Linux installations are unaffected.

References