Junglewise Threat Intelligence

CVE-2026-74941: Mozilla Firefox privilege escalation in Graphics: CanvasWebGL

CVE-2026-74941 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's WebGL graphics rendering engine contained a vulnerability that could allow an attacker to gain elevated privileges within the browser. An exploit of this flaw could enable attackers to bypass browser security boundaries, potentially leading to unauthorized access to user data or malware installation.

Technical details

CVE-2026-74941 is a privilege escalation vulnerability in the Graphics: CanvasWebGL component of Firefox and Thunderbird. The vulnerability requires network access to deliver a malicious web page to a user. When the user visits a crafted webpage, the vulnerability allows code execution with elevated privileges, potentially breaking out of the browser sandbox. Firefox patched this issue in version 154, and Thunderbird in version 154. Firefox ESR received patches in versions 140.14 and 153.1. The root cause and specific attack preconditions are not publicly disclosed.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14 and before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 140.14 and before 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Firefox 154, Firefox ESR 140.14 and 153.1, Thunderbird 154, Thunderbird ESR 140.14 and 153.1

References

Related threats