Junglewise Threat Intelligence

CVE-2026-92053: Mozilla Firefox privilege escalation in Graphics CanvasWebGL

CVE-2026-92053 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox's CanvasWebGL graphics component contains a vulnerability that allows attackers to escalate their privileges. This could enable malicious websites or extensions to gain higher-level access to user data, system resources, or other sensitive operations on an affected browser.

Technical details

This vulnerability is a privilege escalation flaw in the Graphics: CanvasWebGL component of Firefox, caused by incorrect boundary conditions. The bug is exploitable via a network vector, requiring user interaction (visiting a malicious webpage). An attacker can leverage this to execute arbitrary code with elevated privileges within the Firefox sandbox, potentially leading to compromise of the user's browser session and data. The vulnerability has been patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: Vulnerability disclosed alongside Firefox 156 release
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats