ZeroHour

CVE-2026-92011

mass

Privilege Escalation via WebGL Buffer Overflow in Firefox Browsers

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92011 is a privilege escalation vulnerability caused by incorrect boundary conditions (a buffer overflow, CWE-120) in the Graphics: CanvasWebGL component of Mozilla Firefox. An attacker triggers it by convincing a target to visit a malicious web page that feeds crafted data to the WebGL graphics pipeline, requiring user interaction but no authentication. Successful exploitation of this memory corruption flaw allows the attacker to escape the browser's sandbox and execute code with elevated privileges on the victim's machine, with high impact on confidentiality, integrity, and availability. All users running Firefox versions prior to 156 and ESR versions prior to 115.41, 140.16, or 153.3 are affected. No public proof-of-concept exists and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no known exploitation in the wild to date.

What to do: Update immediately to Firefox 156, or to Firefox ESR 115.41, ESR 140.16, or ESR 153.3 depending on your supported branch; enterprise and managed deployments should verify ESR rollout across all endpoints. As an interim hardening measure for systems that cannot be patched promptly, consider disabling WebGL in the browser (about:config, webgl.disabled) to remove the vulnerable code path, and remind users not to visit untrusted sites. Check that automatic updates are enabled, since no exploit mitigation exists in older versions.

Affected
Mozilla Firefoxversions before 156 (fixed in 156)
Mozilla Firefox ESRversions before 115.41 (fixed in 115.41)
Mozilla Firefox ESRversions before 140.16 (fixed in 140.16)
Mozilla Firefox ESRversions before 153.3 (fixed in 153.3)
Estimated exposure
massTens to hundreds of millions of Firefox users (order of magnitude: ~100M+) — Firefox holds roughly 2-3% of the global desktop browser market, which corresponds to well over 100 million active installations worldwide, nearly all of which run an affected release channel until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.

Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.