CVE-2026-92012
massPrivilege Escalation via WebGL Boundary Error in Mozilla Firefox
CVE-2026-92012 is a privilege escalation vulnerability caused by incorrect boundary conditions (CWE-120, an out-of-bounds write) in the Graphics: CanvasWebGL component of Mozilla Firefox. An attacker triggers the flaw by convincing a user to visit a malicious web page that issues specially crafted WebGL canvas operations, which corrupt memory in the browser's graphics code (the CVSS vector requires user interaction). Successful exploitation yields high impact to confidentiality, integrity, and availability, potentially allowing code execution or escape from browser sandbox restrictions. All Firefox users on versions before 156, and enterprise/users on Firefox ESR branches before 115.41, 140.16, and 153.3, are affected. There is no known public proof of concept, and the flaw is not on CISA's Known Exploited Vulnerabilities list, so exploitation status is none known.
What to do: Update Firefox to version 156 or later immediately; Firefox ESR deployments should be upgraded to 115.41, 140.16, or 153.3 on the corresponding branch, ideally pushed centrally via enterprise management tools. Verify that automatic updates are enabled on end-user machines and check for any lingering installations pinned to older ESR branches. Because exploitation requires user interaction (visiting a hostile page), remind users not to browse untrusted sites until patched, though patching is the primary mitigation.
| Mozilla Firefox | versions prior to 156 |
| Mozilla Firefox ESR 115 | versions prior to 115.41 |
| Mozilla Firefox ESR 140 | versions prior to 140.16 |
| Mozilla Firefox ESR 153 | versions prior to 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.