CVE-2026-92013
massWebGL boundary error enables privilege escalation in Mozilla Firefox
Incorrect boundary conditions in the Graphics: CanvasWebGL component of Mozilla Firefox allow an out-of-bounds access (CWE-120) that can be leveraged for privilege escalation, such as escaping the browser's content-process sandbox to execute code with elevated privileges. The flaw is triggered when a victim visits attacker-controlled web content that manipulates a WebGL canvas, requiring no authentication but relying on user interaction (per the CVSS vector UI:R). A successful exploit grants an attacker high impact on confidentiality, integrity, and availability on the victim's machine. All users of Firefox desktop versions prior to the fixed releases, including enterprise ESR deployments, are affected. There is no known public proof of concept and the vulnerability is not listed in CISA's KEV catalog, so exploitation status is currently none known.
What to do: Update immediately to Firefox 156 or the corresponding ESR release (115.41, 140.16, or 153.3) depending on your deployment channel; Firefox's automatic update mechanism should deliver these, but enterprise administrators managing ESR fleets should verify update policies have applied the patched builds. Until patched, users should avoid untrusted sites, since exploitation only requires visiting malicious WebGL content.
| Mozilla Firefox | < 156 (fixed in Firefox 156) |
| Mozilla Firefox ESR 115 | < 115.41 (fixed in Firefox ESR 115.41) |
| Mozilla Firefox ESR 140 | < 140.16 (fixed in Firefox ESR 140.16) |
| Mozilla Firefox ESR 153 | < 153.3 (fixed in Firefox ESR 153.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.