CVE-2020-15654: Medium severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived broken state, especially when interactions with existing browser dialogs and warnings do not work.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-15654?
CVE-2020-15654 is a vulnerability in Mozilla Firefox and Thunderbird that allows a website to make it look like the user is interacting with the user interface when they are not.
How does CVE-2020-15654 work?
CVE-2020-15654 works by specifying a custom cursor using CSS and putting the website in an endless loop, creating a perceived broken state.
What is the severity of CVE-2020-15654?
CVE-2020-15654 has a severity level of low.
Which software versions are affected by CVE-2020-15654?
Mozilla Firefox ESR 78.1, Mozilla Firefox up to version 79, and Mozilla Thunderbird 78.1 are affected by CVE-2020-15654.
How can I resolve CVE-2020-15654?
To resolve CVE-2020-15654, update your Mozilla Firefox or Thunderbird to the latest version provided by Mozilla.