CVE-2026-92052
massUninitialized Memory in Firefox CanvasWebGL Enables Privilege Escalation
A use of uninitialized memory (CWE-457) in the Graphics: CanvasWebGL component of Mozilla Firefox allows privilege escalation (CVSS 8.8, high). The flaw is triggered when a victim visits attacker-controlled web content that exercises the WebGL canvas rendering paths, with the CVSS vector indicating network attack surface, low complexity, no privileges required, but user interaction required. A successful attacker gains elevated privileges in the affected browser process, with high impact on confidentiality, integrity, and availability. Firefox versions before 156 and Firefox ESR versions before 153.3 are affected, and fixes ship in Firefox 156 and Firefox ESR 153.3. No public proof of concept exists, the flaw is not on the CISA KEV list, and exploitation has not been observed in the wild.
What to do: Update to Firefox 156 or later, or Firefox ESR 153.3 or later, and confirm auto-update is enabled (Settings > General > Firefox Updates). Organizations managing ESR deployments should push the ESR 153.3 update via enterprise policy and audit for older ESR branches still in the environment. Because exploitation requires user interaction with malicious web content, blocking untrusted sites until patched offers partial but not sufficient mitigation — patching is the primary control.
| Mozilla Firefox | versions prior to 156 |
| Mozilla Firefox ESR | versions prior to 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Weakness
- CWE-457
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.