Junglewise Threat Intelligence

CVE-2026-92010: Mozilla Firefox privilege escalation in Graphics CanvasWebGL

CVE-2026-92010 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox web browser contains a vulnerability in its graphics rendering component (CanvasWebGL) that allows privilege escalation due to incorrect boundary condition checks. A remote attacker can exploit this to gain elevated privileges and compromise the browser process. This affects multiple Firefox versions and Thunderbird email clients.

Technical details

This vulnerability exists in Firefox's Graphics CanvasWebGL component and is caused by incorrect boundary condition validation. The flaw allows a remote attacker to trigger a privilege escalation by crafting malicious WebGL content served over the network. No special user interaction beyond visiting a malicious website is required. The vulnerability was patched in Firefox 156, Firefox ESR 115.41/140.16/153.3, and Thunderbird 156/140.16/153.3. Multiple related privilege escalation bugs in the same component were also fixed in the same release cycle.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 115.41, 140.16, 153.3
  • Mozilla Thunderbird before 156, 140.16, 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92010 publicly disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41/140.16/153.3, Thunderbird 156/140.16/153.3

References

Related threats