Executive brief
Firefox's WebGL graphics rendering component contains incorrect boundary condition checks that allow attackers to escalate privileges within the browser sandbox. An attacker could exploit this flaw to execute arbitrary code with elevated privileges, potentially compromising browser security and user data.
Technical details
The vulnerability is a privilege escalation in the Graphics: CanvasWebGL component caused by incorrect boundary conditions. Attack requires network access to deliver malicious web content, but no special authentication is needed. An attacker can craft a malicious web page containing CanvasWebGL operations that trigger the boundary condition flaw, allowing code execution with elevated privileges within the browser context. The vulnerability is fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 115.41, 140.16, and 153.3
- Mozilla Thunderbird before 156, 140.16, and 153.3
Timeline
- 2026-09-15: disclosed: Publicly disclosed in Mozilla Security Advisory MFSA2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41/140.16/153.3, and Thunderbird equivalents