Impact
CanvasWebGL processes WebGL commands within Firefox. A flaw in its privilege checks can allow an attacker to elevate privileges inside the browser process, enabling execution of arbitrary code with the same privileges as the user. The weakness corresponds to improper access control (CWE‑284).
Affected Systems
Mozilla Firefox is affected. Versions prior to 154 in the main line, and ESR 140.14 and ESR 153.1, contain the vulnerability. The issue was fixed in those releases.
Risk and Exploitability
EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the CVE notes it as a privilege escalation. Based on the description, the likely attack path is through malicious or crafted WebGL content delivered in a web page, implying a remote exploitation scenario. Without a CVSS score the inherent risk is that an attacker could gain code‑execution privileges within the browser process.
OpenCVE Enrichment