Input validation error in Mozilla products - CVE-2026-92020
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: WebRender component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
Affected software
Firefox ESR
Firefox for Android
How to mitigate CVE-2026-92020
Firefox for Android - update to 156.0
Firefox ESR - addressed in versions 115.41.0, 140.16.0, 153.3.0