Privilege Escalation in CanvasWebGL Component of Firefox by Mozilla
CVE-2026-92052

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92052?

This vulnerability arises from uninitialized memory within the Graphics: CanvasWebGL component, leading to a potential privilege escalation scenario. The flaw allows attackers to potentially exploit this weakness to gain elevated permissions within the affected system. Firefox versions below 156 and Firefox ESR versions below 153.3 have been identified as vulnerable. Promptly upgrading to the latest versions is crucial to ensure system security.

Affected Version(s)

Firefox 153.3

Firefox 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.