ZeroHour

CVE-2026-92009

mass

Privilege Escalation via Out-of-Bounds WebGL Flaw in Mozilla Firefox

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92009 is a privilege escalation vulnerability in Mozilla Firefox's Graphics: CanvasWebGL component, caused by incorrect boundary conditions that result in out-of-bounds memory access (CWE-120, buffer overflow). It is triggered when a victim visits attacker-controlled or compromised web content that invokes malformed WebGL canvas operations, requiring user interaction but no authentication. Successful exploitation allows the attacker to escape the browser's security context and gain elevated privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All users of Firefox releases prior to Firefox 156, and organizations on ESR branches prior to 115.41, 140.16, or 153.3, are affected. No public proof of concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is currently assessed as none known.

What to do: Update immediately to Firefox 156, or Firefox ESR 115.41, 140.16, or 153.3 depending on your branch; verify that auto-update has applied the patch on managed fleets. Enterprise and organization admins should prioritize ESR rollouts and confirm no endpoints remain on unpatched builds. Users should treat untrusted web content cautiously until patched, since the flaw is exploitable via drive-by-style page visits requiring only minimal user interaction.

Affected
Mozilla FirefoxVersions prior to Firefox 156
Mozilla Firefox ESRVersions prior to Firefox ESR 115.41
Mozilla Firefox ESRVersions prior to Firefox ESR 140.16
Mozilla Firefox ESRVersions prior to Firefox ESR 153.3
Estimated exposure
mass≈100-200 million Firefox desktop users potentially exposed until patched — Firefox maintains a global desktop browser user base on the order of 150-200 million across release and ESR channels, and because the flaw is triggerable by any webpage, essentially all unpatched installations are exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.

Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.