CVE-2026-92020
massBoundary Condition Flaw in Firefox WebRender Allows Privilege Escalation
A privilege escalation vulnerability caused by incorrect boundary conditions exists in the Graphics: WebRender rendering component of Mozilla Firefox, classified as CWE-120 (buffer overflow). An attacker can trigger the flaw by persuading a victim to visit maliciously crafted web content, causing WebRender to read or write outside intended memory boundaries during rendering. Successful exploitation can compromise the affected browser process beyond its normal restrictions, with high impact on confidentiality, integrity, and availability, though user interaction is required. The vulnerability affects all Firefox releases prior to Firefox 156 as well as the ESR branches before 115.41, 140.16, and 153.3. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and there is no indication of exploitation in the wild.
What to do: Update Firefox to version 156 or later immediately; organizations on extended support should move to Firefox ESR 115.41, ESR 140.16, or ESR 153.3 as appropriate for their branch. Verify that automatic updates are enabled and confirm deployed browsers have applied the patched release. Because exploitation requires only that a user visit crafted web content, treat this as a high-priority client-side patch for all managed and BYOD endpoints.
| Mozilla Firefox | All versions prior to Firefox 156 |
| Mozilla Firefox ESR 115 | All versions prior to Firefox ESR 115.41 |
| Mozilla Firefox ESR 140 | All versions prior to Firefox ESR 140.16 |
| Mozilla Firefox ESR 153 | All versions prior to Firefox ESR 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.