CVE-2026-92011
massPrivilege Escalation via WebGL Buffer Overflow in Firefox Browsers
CVE-2026-92011 is a privilege escalation vulnerability caused by incorrect boundary conditions (a buffer overflow, CWE-120) in the Graphics: CanvasWebGL component of Mozilla Firefox. An attacker triggers it by convincing a target to visit a malicious web page that feeds crafted data to the WebGL graphics pipeline, requiring user interaction but no authentication. Successful exploitation of this memory corruption flaw allows the attacker to escape the browser's sandbox and execute code with elevated privileges on the victim's machine, with high impact on confidentiality, integrity, and availability. All users running Firefox versions prior to 156 and ESR versions prior to 115.41, 140.16, or 153.3 are affected. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no known exploitation in the wild to date.
What to do: Update immediately to Firefox 156, or to Firefox ESR 115.41, ESR 140.16, or ESR 153.3 depending on your supported branch; enterprise and managed deployments should verify ESR rollout across all endpoints. As an interim hardening measure for systems that cannot be patched promptly, consider disabling WebGL in the browser (about:config, webgl.disabled) to remove the vulnerable code path, and remind users not to visit untrusted sites. Check that automatic updates are enabled, since no exploit mitigation exists in older versions.
| Mozilla Firefox | versions before 156 (fixed in 156) |
| Mozilla Firefox ESR | versions before 115.41 (fixed in 115.41) |
| Mozilla Firefox ESR | versions before 140.16 (fixed in 140.16) |
| Mozilla Firefox ESR | versions before 153.3 (fixed in 153.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.