Description
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CanvasWebGL processes WebGL commands within Firefox. A flaw in its privilege checks can allow an attacker to elevate privileges inside the browser process, enabling execution of arbitrary code with the same privileges as the user. The weakness corresponds to improper access control (CWE‑284).

Affected Systems

Mozilla Firefox is affected. Versions prior to 154 in the main line, and ESR 140.14 and ESR 153.1, contain the vulnerability. The issue was fixed in those releases.

Risk and Exploitability

EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the CVE notes it as a privilege escalation. Based on the description, the likely attack path is through malicious or crafted WebGL content delivered in a web page, implying a remote exploitation scenario. Without a CVSS score the inherent risk is that an attacker could gain code‑execution privileges within the browser process.

Generated by OpenCVE AI on August 18, 2026 at 13:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox to version 154 or newer, or to ESR 140.14 or later, or ESR 153.1 or later, to apply the official fix.
  • If an immediate update is not possible, disable or restrict WebGL by setting dom.webgl.disabled=true in about:config or via enterprise group policy.
  • Apply browser‑level policies or a strict Content Security Policy to limit or block untrusted WebGL scripts.

Generated by OpenCVE AI on August 18, 2026 at 13:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-284
CWE-285
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Privilege escalation in the Graphics: CanvasWebGL component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:28.747Z

Reserved: 2026-08-17T11:57:39.938Z

Link: CVE-2026-74941

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T13:17:30.513

Modified: 2026-08-18T14:49:11.260

Link: CVE-2026-74941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses