Executive brief
Firefox and Thunderbird browsers contain a flaw in their graphics rendering component (CanvasWebGL) that allows attackers to escalate privileges due to incorrect boundary condition checks. An attacker could exploit this to execute code with elevated privileges, potentially compromising browser security and user data.
Technical details
The vulnerability is a privilege escalation flaw in the Graphics: CanvasWebGL component caused by incorrect boundary condition checks. The WebGL canvas rendering implementation fails to properly validate buffer boundaries, allowing an attacker to read or write memory outside intended bounds. Exploitation requires user interaction (visiting a malicious webpage), but no authentication is required. A successful exploit allows an attacker to escalate privileges and potentially execute arbitrary code within the browser context. Patches are available in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 115.41, 140.x before 140.16, 153.x before 153.3
- Mozilla Thunderbird before 156, 140.x before 140.16, 153.x before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, Thunderbird 156, 140.16, 153.3