CVE-2026-92009
massPrivilege Escalation via Out-of-Bounds WebGL Flaw in Mozilla Firefox
CVE-2026-92009 is a privilege escalation vulnerability in Mozilla Firefox's Graphics: CanvasWebGL component, caused by incorrect boundary conditions that result in out-of-bounds memory access (CWE-120, buffer overflow). It is triggered when a victim visits attacker-controlled or compromised web content that invokes malformed WebGL canvas operations, requiring user interaction but no authentication. Successful exploitation allows the attacker to escape the browser's security context and gain elevated privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All users of Firefox releases prior to Firefox 156, and organizations on ESR branches prior to 115.41, 140.16, or 153.3, are affected. No public proof of concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is currently assessed as none known.
What to do: Update immediately to Firefox 156, or Firefox ESR 115.41, 140.16, or 153.3 depending on your branch; verify that auto-update has applied the patch on managed fleets. Enterprise and organization admins should prioritize ESR rollouts and confirm no endpoints remain on unpatched builds. Users should treat untrusted web content cautiously until patched, since the flaw is exploitable via drive-by-style page visits requiring only minimal user interaction.
| Mozilla Firefox | Versions prior to Firefox 156 |
| Mozilla Firefox ESR | Versions prior to Firefox ESR 115.41 |
| Mozilla Firefox ESR | Versions prior to Firefox ESR 140.16 |
| Mozilla Firefox ESR | Versions prior to Firefox ESR 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.