Executive brief
A flaw in Firefox's graphics rendering engine (WebRender) allows unprivileged code to escalate its privileges due to incorrect boundary checks. An attacker exploiting this vulnerability could gain elevated system permissions and potentially execute arbitrary code, compromising user data, browser security, and system integrity.
Technical details
CVE-2026-92020 is a privilege escalation vulnerability caused by incorrect boundary conditions in the Graphics: WebRender component of Firefox. The vulnerability allows code running within the browser sandbox to bypass memory safety checks and escalate privileges. The attack vector is local/adjacent and requires no additional user interaction beyond visiting a malicious webpage or viewing crafted content in the browser. A successful exploit grants the attacker elevated privileges within or beyond the Firefox sandbox, potentially enabling arbitrary code execution. Mozilla has issued patches in Firefox 156, Firefox ESR 115.41, 140.16, and 153.3, as well as Thunderbird 156, 140.16, and 153.3.
Affected products
- Mozilla Firefox below 156
- Mozilla Firefox ESR 115.x before 115.41, 140.x before 140.16, 153.x before 153.3
- Mozilla Thunderbird below 156, 140.x before 140.16, 153.x before 153.3
Timeline
- 2026-09-15: disclosed: Security vulnerability disclosed in Mozilla security advisory MFSA2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, Thunderbird 156, 140.16, 153.3