Executive brief
A privilege escalation vulnerability exists in Firefox's Graphics CanvasWebGL component due to incorrect boundary condition checks. An attacker could exploit this flaw to gain elevated privileges and potentially compromise system security or steal sensitive user data. Mozilla has released patched versions of Firefox, Firefox ESR, and Thunderbird to address this issue.
Technical details
The vulnerability is a privilege escalation flaw in the Graphics: CanvasWebGL component caused by incorrect boundary conditions. The vulnerability is remotely exploitable via the network as part of normal web browsing (visiting a malicious website). No user interaction beyond normal browsing is required. A successful exploit allows an attacker to escalate privileges and potentially gain arbitrary code execution or access to sensitive data. Mozilla has released fixes in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox Below 156
- Mozilla Firefox ESR Below 115.41, 140.x before 140.16, 153.x before 153.3
- Mozilla Thunderbird Below 156, 140.x before 140.16, 153.x before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92006 disclosed in Mozilla Foundation Security Advisory 2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3