ZeroHour

CVE-2026-92052

mass

Uninitialized Memory in Firefox CanvasWebGL Enables Privilege Escalation

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

A use of uninitialized memory (CWE-457) in the Graphics: CanvasWebGL component of Mozilla Firefox allows privilege escalation (CVSS 8.8, high). The flaw is triggered when a victim visits attacker-controlled web content that exercises the WebGL canvas rendering paths, with the CVSS vector indicating network attack surface, low complexity, no privileges required, but user interaction required. A successful attacker gains elevated privileges in the affected browser process, with high impact on confidentiality, integrity, and availability. Firefox versions before 156 and Firefox ESR versions before 153.3 are affected, and fixes ship in Firefox 156 and Firefox ESR 153.3. No public proof of concept exists, the flaw is not on the CISA KEV list, and exploitation has not been observed in the wild.

What to do: Update to Firefox 156 or later, or Firefox ESR 153.3 or later, and confirm auto-update is enabled (Settings > General > Firefox Updates). Organizations managing ESR deployments should push the ESR 153.3 update via enterprise policy and audit for older ESR branches still in the environment. Because exploitation requires user interaction with malicious web content, blocking untrusted sites until patched offers partial but not sufficient mitigation — patching is the primary control.

Affected
Mozilla Firefoxversions prior to 156
Mozilla Firefox ESRversions prior to 153.3
Estimated exposure
mass≈100M+ users (order of magnitude: hundreds of millions of Firefox installations, plus enterprise ESR fleets) — Firefox is estimated to have roughly 150–200 million users worldwide (~2–3% desktop browser share) per public usage reports, so any client-side flaw affecting unpatched versions plausibly reaches a nine-figure user base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Weakness
CWE-457
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.