Junglewise Threat Intelligence

CVE-2026-12324: Mozilla Firefox incorrect boundary conditions in CanvasWebGL

CVE-2026-12324 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used to access the internet. A vulnerability was found in the component responsible for rendering 3D graphics (WebGL), which could potentially lead to unexpected behavior or crashes when processing specific web content. Users are advised to update to the latest version to maintain browser stability and security.

Technical details

A vulnerability exists in the Graphics: CanvasWebGL component of Mozilla Firefox due to incorrect boundary conditions. An attacker could potentially exploit this by tricking a user into visiting a specially crafted website that utilizes WebGL. While the specific impact is categorized as low severity by the vendor, boundary condition errors typically lead to out-of-bounds reads or writes, which can result in application instability or denial-of-service. The issue is fixed in Firefox 152 and Firefox ESR 140.12.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched

References

Related threats