CVE-2026-92006
massPrivilege Escalation via Boundary Error in Mozilla Firefox CanvasWebGL
Mozilla Firefox contains a privilege escalation vulnerability caused by incorrect boundary conditions in the Graphics: CanvasWebGL component, classified as CWE-120 (buffer overflow). An attacker can trigger the flaw by convincing a user to visit a maliciously crafted web page that exploits WebGL rendering operations, since user interaction is required per the CVSS vector. Successful exploitation allows the attacker to escape the browser's sandbox and execute code with elevated privileges, impacting confidentiality, integrity, and availability. All users of Firefox release builds before version 156 and ESR builds before 115.41, 140.16, or 153.3 are affected across Windows, macOS, and Linux. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation at this time.
What to do: Update Firefox to version 156 or later immediately; enterprise and organizational users on extended support should move to Firefox ESR 115.41, ESR 140.16, or ESR 153.3 depending on their branch. Verify that automatic updates are enabled and audit managed fleets for lagging ESR versions, since exploitation requires only that a user visit attacker-controlled web content. Until patched, users should avoid untrusted websites and links, and defenders should monitor for post-exploitation activity consistent with sandbox escape.
| Mozilla Firefox | < 156 |
| Mozilla Firefox ESR 115 | < 115.41 |
| Mozilla Firefox ESR 140 | < 140.16 |
| Mozilla Firefox ESR 153 | < 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.