Junglewise Threat Intelligence

CVE-2026-92009: Mozilla Firefox privilege escalation in CanvasWebGL

CVE-2026-92009 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox's WebGL canvas graphics component contains a boundary condition flaw that allows attackers to escalate privileges. A malicious webpage could exploit this vulnerability to gain elevated access and perform unauthorized actions on a user's system.

Technical details

CVE-2026-92009 is a privilege escalation vulnerability in the Graphics: CanvasWebGL component caused by incorrect boundary condition handling. The flaw allows an attacker to bypass memory safety checks through specially crafted WebGL operations. Attack vector is network-based requiring user interaction (visiting a malicious webpage). Successful exploitation grants the attacker elevated privileges within the browser sandbox. The vulnerability was patched in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 115.41, 140.16, and 153.3
  • Mozilla Thunderbird before 156, 140.16, and 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41/140.16/153.3, Thunderbird 156/140.16/153.3

References

Related threats