Executive brief
A security vulnerability has been identified in the WebRender component of the Mozilla Firefox web browser. This flaw could allow an attacker to gain elevated privileges on a user's system, potentially leading to unauthorized access to sensitive data or the ability to execute restricted operations. Users are advised to update to the latest versions of Firefox or Firefox ESR to mitigate this risk.
Technical details
A privilege escalation vulnerability exists in the Graphics: WebRender component of Mozilla Firefox. While specific root cause details are restricted in the associated Bugzilla report (Bug 2023443), the advisory classifies the impact as 'high' and indicates it allows for privilege escalation. The vulnerability likely involves a flaw in how the browser handles GPU-accelerated rendering, which could be exploited by a malicious website to bypass security boundaries. The issue is resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. Exploitation typically requires a user to visit a specially crafted webpage.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12, < 115.37
Timeline
- 2026-06-16: disclosed: Initial advisory publication by Mozilla
- 2026-06-16: patched: Fixed in Firefox 152, ESR 140.12, and ESR 115.37