CVE-2026-92008
massBoundary Condition Privilege Escalation in Mozilla Firefox CanvasWebGL (CVE-2026-92008)
CVE-2026-92008 is a privilege escalation vulnerability caused by incorrect boundary conditions (a buffer overflow, CWE-120) in Firefox's Graphics: CanvasWebGL component. An attacker can trigger the flaw by convincing a user to visit a malicious web page that feeds specially crafted WebGL/Canvas content to the browser, which requires user interaction per the CVSS vector. Successful exploitation allows the attacker to escape normal browser content-process restrictions and gain elevated privileges with high impact to confidentiality, integrity, and availability. All users running Firefox releases older than Firefox 156, and enterprise users on ESR branches older than ESR 115.41, ESR 140.16, or ESR 153.3, are affected. No public proof of concept exists, the issue is not in CISA's KEV catalog, and no exploitation in the wild is currently known.
What to do: Update all Firefox desktop installations to Firefox 156 or later, and update ESR deployments to ESR 115.41, ESR 140.16, or ESR 153.3 or later depending on the branch in use. Enterprises should push these builds via update management tooling and verify ESR channel assignments. If immediate patching is not possible, disabling WebGL (e.g., via about:config 'webgl.disabled' or enterprise policy) is a temporary workaround that reduces attack surface for this component.
| Mozilla Firefox | Firefox versions prior to Firefox 156 |
| Mozilla Firefox ESR | Firefox ESR versions prior to ESR 115.41 (115.x branch) |
| Mozilla Firefox ESR | Firefox ESR versions prior to ESR 140.16 (140.x branch) |
| Mozilla Firefox ESR | Firefox ESR versions prior to ESR 153.3 (153.x branch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.