Mozilla Foundation Security Advisory 2015-35
Cursor clickjacking with flash and images
- Announced
- March 31, 2015
- Reporter
- Jordi Chancel
- Impact
- Moderate
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 37
- SeaMonkey 2.35
Description
Security researcher Jordi Chancel reported a mechanism that made cursor invisible through flash content and then replaced it through the layering of HTML content. This flaw can be in used in combination with an image of the cursor manipulated through JavaScript, leading to clickjacking during subsequent interactions with HTML content.
This flaw only affects OS X systems. Windows and Linux installations are unaffected.