Executive brief
Firefox's CanvasWebGL graphics component contains a site isolation vulnerability that allows attackers to bypass security boundaries between websites. An exploit could enable a malicious website to access data from other sites a user is visiting in the same browser session, compromising user privacy and potentially exposing sensitive information.
Technical details
A site isolation bypass vulnerability exists in the Graphics: CanvasWebGL component of Firefox and Thunderbird. The vulnerability is rooted in insufficient isolation between different security origins when rendering WebGL content on canvas elements. An attacker can craft a malicious webpage that, when visited by a user, leverages the CanvasWebGL component to break site isolation boundaries and access data from other sites open in the same browser context. User interaction (visiting the malicious site) is required for exploitation. The vulnerability has been patched in Firefox 154, Firefox ESR 115.39, 140.14, and 153.1, and corresponding Thunderbird versions.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 115.39
- Mozilla Firefox ESR before 140.14
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 140.14
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed: Vulnerability disclosed by Mozilla Foundation Security Advisory MFSA2026-74
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 115.39, 140.14, 153.1, Thunderbird 154, 140.14, 153.1