Executive brief
A use-after-free vulnerability in Firefox's Canvas2D graphics component allows attackers to achieve privilege escalation. Firefox's Canvas2D is used by websites to render dynamic graphics and animations in the browser. An attacker could exploit this flaw to gain unauthorized access or crash the browser, potentially affecting any user viewing a malicious webpage.
Technical details
This is a use-after-free vulnerability in the Graphics: Canvas2D component of Mozilla Firefox. A use-after-free occurs when a program attempts to access memory that has already been freed, which can lead to code execution or information disclosure. The vulnerability is reachable via network vectors (visiting a malicious webpage) without requiring authentication or special user interaction beyond normal browsing. An attacker can leverage this flaw to escalate privileges and gain control of the affected process. The vulnerability has been patched in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, and corresponding Thunderbird versions.
Affected products
- Mozilla Firefox Before 154
- Mozilla Firefox ESR Before 140.14, 153.1
- Mozilla Thunderbird Before 154, 140.14, 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1