Impact
A flaw in the Graphics: CanvasWebGL component allows an attacker to elevate their privileges within the affected application. The vulnerability permits code to gain higher privileges than intended, potentially enabling access to protected resources or execution of sensitive operations. The weakness is classified as CWE-269, indicating a flaw in the management of access controls for privileged functionality.
Affected Systems
Affected vendors include Mozilla, specifically Firefox and Thunderbird. The issue exists in all Firefox versions prior to 156 and in Thunderbird before version 156, with the ESR branch fixed in Firefox ESR 153.3. Users running earlier releases are at risk.
Risk and Exploitability
The CVSS score of 8.8 marks this as a high‑severity vulnerability, suggesting significant impact once exploited. EPSS data is not currently available, so the exact likelihood of exploitation remains uncertain, though the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the component, the likely attack vector is through a malicious web page or content that triggers WebGL operations; this inference is drawn from the description of a privilege escalation in a graphics component.
OpenCVE Enrichment