Junglewise Threat Intelligence

CVE-2026-92011: Mozilla Firefox privilege escalation in Graphics CanvasWebGL

CVE-2026-92011 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox's WebGL graphics component contains boundary condition flaws that allow attackers to escalate privileges and potentially execute arbitrary code. An attacker could exploit this vulnerability through a malicious web page to escape the browser's security sandbox and gain elevated system access, compromising user data and system integrity.

Technical details

This is a privilege escalation vulnerability (CVE-2026-92011) stemming from incorrect boundary condition checks in the Graphics: CanvasWebGL component of Firefox, Firefox ESR, and Thunderbird. The WebGL graphics API fails to properly validate memory boundaries when processing graphics operations, allowing an attacker to read or write out-of-bounds memory. A network-based attacker can exploit this by crafting a malicious webpage that triggers the vulnerability through WebGL API calls; no user interaction or authentication is required beyond visiting the page. Successful exploitation allows privilege escalation, potentially enabling sandbox escape and arbitrary code execution. The vulnerability is fixed in Firefox 156, Firefox ESR 115.41/140.16/153.3, and Thunderbird 156/140.16/153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 115.41, 140.16, 153.3
  • Mozilla Thunderbird before 156, 140.16, 153.3

Timeline

  • 2026-09-15: disclosed: Published in Mozilla Security Advisory MFSA2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41/140.16/153.3, Thunderbird 156/140.16/153.3

References

Related threats