Mozilla Firefox and Firefox ESR Sandbox Escape Vulnerability in WebGL Component

Vulnerability

A sandbox escape vulnerability has been identified in Mozilla Firefox versions prior to 147 and Firefox ESR versions prior to 140.7. This vulnerability arises from incorrect boundary conditions in the Graphics: CanvasWebGL component, allowing for potential exploitation.

Impact

Exploitation of this vulnerability leads to a sandbox escape, allowing potentially malicious content to break out of its restricted environment and interact with the broader system or application.

Remediation

Users can upgrade to Firefox 147 or Firefox ESR 140.7 to address this vulnerability.

Added: Jan 13, 2026, 2:35 PM
Updated: Jan 13, 2026, 6:51 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
1.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.