Impact
CanvasWebGL is the component responsible for handling WebGL content in Firefox. A vulnerability within that component allows an attacker to bypass normal privilege checks, elevating privileges inside the browser process. By delivering malicious WebGL content through a web page, an attacker could potentially execute arbitrary code with the same user privileges. The flaw represents an improper privilege management weakness, including unauthorized privilege escalation (CWE-266, CWE-269). Based on the description, it is inferred that the vulnerability can be triggered by delivering malicious WebGL content via a web page.
Affected Systems
Firefox versions prior to 154, as well as Firefox ESR releases older than 140.14 and older than 153.1, are vulnerable. Thunderbird releases prior to 154, 140.14, or 153.1 are also affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and EPSS data is available with a low but nonzero exploitation probability (0.00323, < 1%). The vulnerability is not listed in the CISA KEV catalog, yet the risk remains significant. Based on the description, it is inferred that the likely attack vector involves malicious or crafted WebGL content delivered in a web page, implying remote exploitation would result in privileged code execution within the browser process.
OpenCVE Enrichment
Debian DLA
Debian DSA