CVE-2026-92014
massGraphics Buffer Overflow Enables Privilege Escalation in Firefox ESR
Mozilla Firefox ESR contains a privilege escalation vulnerability caused by incorrect boundary conditions (a classic buffer overflow, CWE-120) in the browser's Graphics component. Exploitation is network-reachable but requires user interaction, meaning a victim must be convinced to open crafted content (such as a malicious web page or media) that triggers the vulnerable graphics-rendering path. A successful exploit could allow an attacker to escalate privileges on the affected system, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 8.8). The flaw affects Firefox ESR 115.x releases before 115.41 and Firefox ESR 140.x releases before 140.16; the advisory data names only these ESR branches as affected. There is no known public proof of concept, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Upgrade immediately to Firefox ESR 115.41 (if on the 115 branch) or Firefox ESR 140.16 (if on the 140 branch), pushing the update centrally via enterprise tooling (MDM, Group Policy, or Puppet) where ESR is deployed. Audit installed browser versions to catch machines lingering on older ESR builds. Because exploitation requires user interaction, remind users not to open untrusted links or content, but treat patching as the primary mitigation.
| Mozilla Firefox ESR | 115.x before 115.41 |
| Mozilla Firefox ESR | 140.x before 140.16 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.