Executive brief
Firefox's WebGL graphics component contains a boundary condition vulnerability that allows privilege escalation. An attacker can exploit this flaw to gain elevated permissions and potentially execute code with higher privileges. The vulnerability affects multiple versions of Firefox and related products across desktop and mobile platforms.
Technical details
This vulnerability is a privilege escalation flaw caused by incorrect boundary conditions in the Graphics: CanvasWebGL component of Mozilla Firefox. The vulnerability resides in WebGL rendering code (referenced as Bug 2058069) and allows an attacker to bypass memory safety checks through carefully crafted boundary condition attacks. Exploitation likely requires user interaction such as visiting a malicious webpage or viewing specially crafted content. An attacker can achieve arbitrary code execution with elevated privileges. The vulnerability has been fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR 115 before 115.41, 140 before 140.16, 153 before 153.3
- Mozilla Thunderbird before 156, 140 before 140.16, 153 before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92012 published in Mozilla Security Advisory MFSA2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, Thunderbird 156, 140.16, 153.3