Junglewise Threat Intelligence

CVE-2026-74946: Mozilla Firefox privilege escalation in Graphics CanvasWebGL

CVE-2026-74946 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's WebGL canvas graphics component contains a vulnerability that allows attackers to escalate privileges due to incorrect boundary condition checking. An attacker who exploits this flaw could break out of Firefox's security sandbox and execute arbitrary code with elevated permissions, potentially compromising user systems and data.

Technical details

The vulnerability exists in Firefox's Graphics: CanvasWebGL component and stems from incorrect boundary conditions that fail to properly validate memory access constraints. The flaw allows privilege escalation, which in a sandboxed browser context means an attacker can escape the renderer sandbox or achieve code execution with elevated privileges. The vulnerability is reachable via network vectors and can be triggered through malicious web content. Mozilla has patched this issue in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, along with corresponding Thunderbird versions (154, 140.14, 153.1).

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 115.39, 140.x before 140.14, 153.x before 153.1
  • Mozilla Thunderbird before 154, 140.x before 140.14, 153.x before 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Firefox 154, Firefox ESR 115.39/140.14/153.1, Thunderbird 154/140.14/153.1

References

Related threats