CVE-2026-92007
massPrivilege Escalation via WebGL Boundary Flaw in Mozilla Firefox
Mozilla Firefox contains a privilege escalation vulnerability caused by incorrect boundary conditions (a classic buffer overflow, CWE-120) in the Graphics: CanvasWebGL component. An attacker triggers the flaw by convincing a victim to visit a maliciously crafted web page that manipulates WebGL canvas operations, overflowing a buffer and potentially executing code with elevated privileges beyond the browser's normal constraints. Successful exploitation gives the attacker high impact on confidentiality, integrity, and availability of the victim's system, consistent with the CVSS 8.8 rating. All users of Firefox release and ESR builds that have not applied the fixes are affected, since the bug spans the current release channel and three ESR branches. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation to date.
What to do: Update immediately: standard Firefox users should move to Firefox 156, and enterprise/ESR deployments should upgrade to Firefox ESR 115.41, ESR 140.16, or ESR 153.3 depending on their branch. Verify that automatic updates are enabled on managed fleets, as ESR deployments often lag on patching. As a temporary mitigation for systems that cannot be patched right away, consider disabling WebGL content or restricting untrusted sites, since exploitation requires the victim to render malicious WebGL canvas content.
| Mozilla Firefox | Versions prior to Firefox 156 |
| Mozilla Firefox ESR | ESR branches prior to Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.