Executive brief
Firefox's WebGL canvas rendering component contains a memory initialization vulnerability that can be exploited to escalate privileges and potentially escape the browser sandbox. An attacker could leverage this to gain elevated access on a user's system or execute malicious code with higher permissions than the browser normally allows.
Technical details
This vulnerability exists in the Graphics: CanvasWebGL component of Firefox and stems from uninitialized memory that fails to be properly sanitized before use in graphics operations. The uninitialized memory can contain sensitive data from previous operations, which an attacker can read or manipulate through WebGL canvas operations to achieve privilege escalation. The vulnerability is reachable over the network through malicious web content and does not require user authentication beyond visiting a compromised or attacker-controlled website. An attacker can exploit this to escape the browser sandbox and gain elevated privileges on the underlying system. The vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3