ZeroHour

CVE-2026-92010

mass

WebGL Canvas Buffer Overflow Privilege Escalation in Mozilla Firefox

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Mozilla Firefox contains a privilege escalation flaw caused by incorrect boundary conditions (CWE-120, buffer overflow) in the Graphics: CanvasWebGL component. An attacker can trigger it by convincing a target user to visit a web page that feeds specially crafted data to the WebGL canvas rendering pipeline, requiring no privileges but some user interaction. Successful exploitation yields high impact on confidentiality, integrity, and availability, meaning an attacker could potentially escape the content-process sandbox and execute code with elevated browser privileges. All users of Firefox release and ESR branches prior to the fixed versions are affected. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update immediately to Firefox 156, or to Firefox ESR 115.41, 140.16, or 153.3 depending on your ESR branch. Verify that automatic updates are enabled on managed endpoints, and check enterprise/ESR deployments where updates are often staggered or deferred. Since exploitation requires only a user visiting a malicious page, treat unpatched browsers as high priority for patching this cycle.

Affected
Mozilla Firefoxversions prior to 156
Mozilla Firefox ESRversions prior to 115.41
Mozilla Firefox ESRversions prior to 140.16
Mozilla Firefox ESRversions prior to 153.3
Estimated exposure
mass≈150–200 million users potentially affected (unpatched Firefox desktop installs) — Mozilla Firefox maintains a global desktop user base commonly estimated in the 150–200 million range, so all installations that have not yet applied the fixed releases fall within that order of magnitude.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.

Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.