ZeroHour

CVE-2026-92053

mass

Privilege Escalation in Firefox CanvasWebGL Component (CVE-2026-92053)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92053 is a privilege escalation vulnerability (CWE-269, improper privilege management) in Firefox's Graphics: CanvasWebGL component. Exploitation requires a victim to interact with attacker-controlled content, such as visiting a malicious web page that abuses WebGL handling, after which the attacker can gain improperly elevated privileges. With a CVSS 3.1 base score of 8.8 (high) and full impact on confidentiality, integrity, and availability, successful exploitation could allow an attacker to break out of normal browser content-process restrictions and execute code or access data with elevated privileges. All users of Firefox release builds before version 156 and Firefox ESR builds before 153.3 are affected. Mozilla has shipped fixes, and no public proof of concept or known in-the-wild exploitation has been reported, nor is the issue listed in CISA's KEV catalog.

What to do: Update immediately to Firefox 156 or later (release channel) or Firefox ESR 153.3 or later (enterprise/extended support channel), and verify that automatic updates have applied the patch. Enterprise administrators should push the patched ESR build via their deployment tools and confirm no unmanaged Firefox installations remain on older versions. Although no exploitation has been observed, the high CVSS score and browser-based attack surface (drive-by style via crafted web content) make prompt patching a priority.

Affected
Mozilla Firefoxversions prior to Firefox 156 (fixed in 156)
Mozilla Firefox ESRversions prior to Firefox ESR 153.3 (fixed in 153.3)
Estimated exposure
massHundreds of millions of users — Firefox's estimated global user base is on the order of 150-200M+ across desktop and mobile — Firefox is a mass-market browser with a globally installed base estimated at well over 150 million users, and the vulnerable CanvasWebGL code path is enabled by default in standard configurations, so the default-installed population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.