Description
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Site isolation in the Graphics: CanvasWebGL component allows a malicious webpage to access or manipulate a WebGL rendering context belonging to a different origin. The flaw sidesteps the browser’s same‑origin policy for graphics processing, enabling attackers to read sensitive data, perform cross‑site tracing, or alter the appearance or state of unrelated web applications. The impact is a compromise of confidentiality and integrity for any content rendered in WebGL.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are impacted. Versions before Firefox 154 and all ESR branches older than 115.39, 140.14, and 153.1, and Thunderbird versions older than 154 and ESR branches older than 140.14 and 153.1, are vulnerable.

Risk and Exploitability

The CVSS score of 7.5 ranks this as medium‑to‑high severity. The EPSS score is below 1 %, indicating a low but nonzero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Exploitation requires a malicious webpage that can execute WebGL code, likely via social engineering or drive‑by download. In affected browsers with WebGL enabled, this can be achieved by a single page visit, making the attack path straightforward once the user loads a malicious site.

Generated by OpenCVE AI on August 21, 2026 at 22:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or a later ESR release (115.39, 140.14, or 153.1).
  • Upgrade to Thunderbird 154 or a later ESR release (140.14 or 153.1).
  • Check that browser site isolation settings are enabled to prevent cross‑origin access to WebGL contexts.
  • If an upgrade is not immediately feasible, disable WebGL or restrict site isolation policies via browser configuration or content security policies.

Generated by OpenCVE AI on August 21, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Fri, 21 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-346
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-653
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-200
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Site isolation issue in the Graphics: CanvasWebGL component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-21T20:09:50.955Z

Reserved: 2026-08-17T11:57:25.126Z

Link: CVE-2026-74934

cve-icon Vulnrichment

Updated: 2026-08-21T20:09:40.817Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:29.620

Modified: 2026-08-24T15:54:34.060

Link: CVE-2026-74934

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T12:23:27Z

Links: CVE-2026-74934 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:00:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-346

    Origin Validation Error

  • CWE-653

    Improper Isolation or Compartmentalization