CVE-2026-92053
massPrivilege Escalation in Firefox CanvasWebGL Component (CVE-2026-92053)
CVE-2026-92053 is a privilege escalation vulnerability (CWE-269, improper privilege management) in Firefox's Graphics: CanvasWebGL component. Exploitation requires a victim to interact with attacker-controlled content, such as visiting a malicious web page that abuses WebGL handling, after which the attacker can gain improperly elevated privileges. With a CVSS 3.1 base score of 8.8 (high) and full impact on confidentiality, integrity, and availability, successful exploitation could allow an attacker to break out of normal browser content-process restrictions and execute code or access data with elevated privileges. All users of Firefox release builds before version 156 and Firefox ESR builds before 153.3 are affected. Mozilla has shipped fixes, and no public proof of concept or known in-the-wild exploitation has been reported, nor is the issue listed in CISA's KEV catalog.
What to do: Update immediately to Firefox 156 or later (release channel) or Firefox ESR 153.3 or later (enterprise/extended support channel), and verify that automatic updates have applied the patch. Enterprise administrators should push the patched ESR build via their deployment tools and confirm no unmanaged Firefox installations remain on older versions. Although no exploitation has been observed, the high CVSS score and browser-based attack surface (drive-by style via crafted web content) make prompt patching a priority.
| Mozilla Firefox | versions prior to Firefox 156 (fixed in 156) |
| Mozilla Firefox ESR | versions prior to Firefox ESR 153.3 (fixed in 153.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.