CVE-2026-12324: Firefox & Thunderbird WebGL Boundary Condition Vulnerability
A boundary condition flaw in Firefox and Thunderbird's WebGL graphics component allows an attacker to send a specially crafted request over the network without authentication or user interaction to cause information disclosure, data manipulation, or denial of service. The vulnerability affects multiple versions of both applications and has been patched in recent releases.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.3 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-703
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-17
NVD description (verbatim)
Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12324 is a boundary condition vulnerability (CWE-703) in the Graphics: CanvasWebGL component affecting Mozilla Firefox and Thunderbird. The flaw permits improper memory or resource handling when processing WebGL canvas operations, potentially leading to information exposure, integrity compromise, or service disruption. The vulnerability is remotely exploitable with no authentication required and does not depend on user interaction, though it requires network access to the affected application. CVSS v3.1 base score is 7.3 (HIGH severity, vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Business impact
Organizations and users relying on Firefox or Thunderbird face risk of data leakage, content tampering, or application crashes via malicious web pages or network-based attacks. Vulnerable browser instances may be leveraged as entry points for credential theft or lateral movement if combined with other attack chains. The high CVSS score and low attack complexity mean this threat should be prioritized in patch management cycles to reduce exposure window.
Affected systems
Mozilla Firefox (versions prior to 152), Firefox ESR (versions prior to 140.12), Mozilla Thunderbird (versions prior to 152), and Thunderbird ESR (versions prior to 140.12) are affected. Any system running these applications without the patched versions is susceptible. Organizations with managed browser deployments or Thunderbird-based email clients should verify version compliance across their fleet.
Exploitability
The vulnerability is remotely exploitable with a network attack vector and no authentication requirement. Exploitation does not depend on user interaction, making it suitable for automated or large-scale attack scenarios. An attacker could host a malicious webpage or deliver crafted network traffic that triggers the boundary condition flaw. The low attack complexity and direct network accessibility elevate the practical exploitability risk.
Remediation
Apply security updates immediately: upgrade Firefox to version 152 or later, Firefox ESR to version 140.12 or later, Thunderbird to version 152 or later, and Thunderbird ESR to version 140.12 or later. Verify application versions through Help > About menus in Firefox/Thunderbird, which will also prompt automatic updates if configured. Organizations should prioritize this patch in their change management process given the HIGH severity rating and ease of exploitation.
Patch guidance
Firefox and Thunderbird auto-update functionality should be enabled to receive patches automatically. Manual patching can be performed by navigating Help > About in the application; the system will check for and install available updates. For Thunderbird and Firefox ESR branches, ensure deployment of the specified ESR patch levels (140.12 for ESR users). Organizations managing multiple installations should use group policies or enterprise deployment tools to ensure version compliance across endpoints before the vulnerability can be exploited in the wild.
Detection guidance
Monitor application logs and network traffic for abnormal WebGL canvas operations or resource allocation failures that correlate with browser crashes or instability. Endpoint detection and response (EDR) tools should flag attempts to access or manipulate WebGL components in unusual ways. Network-based detection is challenging without payload signatures; focus on patch deployment verification and behavioral anomalies in browser processes. Track Firefox and Thunderbird versions across your environment using software inventory or endpoint management systems to identify non-compliant systems.
Why prioritize this
This vulnerability scores HIGH (7.3 CVSS) with remote exploitability, no authentication, and no user interaction required. The combination of low attack complexity and broad confidentiality, integrity, and availability impact makes it a realistic threat vector. The fact it is not yet on CISA's KEV catalog does not diminish urgency—boundary condition flaws in rendering engines are historically favored by sophisticated threat actors. Patch immediately to reduce attack surface.
Risk score, explained
The CVSS 3.1 score of 7.3 reflects the alignment of network accessibility (AV:N), low attack complexity (AC:L), no authentication (PR:N), and no user interaction (UI:N) with partial impacts across confidentiality, integrity, and availability. The unscoped nature (S:U) limits the impact radius to the vulnerable component but does not reduce exploitability. This places the vulnerability firmly in the HIGH severity tier, warranting urgent remediation.
Frequently asked questions
Can I be exploited if I don't visit untrusted websites?
Yes. While visiting a malicious webpage is one attack vector, the vulnerability can also be triggered via compromised advertisements, third-party embeds, or network-level attacks if an attacker can intercept or inject WebGL-related traffic. Exploitation does not require user interaction, so passive exposure is sufficient.
Does CISA's KEV catalog include this vulnerability?
No, CVE-2026-12324 is not currently listed on CISA's Known Exploited Vulnerabilities catalog. However, absence from the KEV list does not indicate low risk—it may reflect the recency of disclosure or low public exploit availability rather than actual threat level. The HIGH CVSS score and low attack complexity warrant immediate patching regardless of KEV status.
Will automatic updates protect me without action on my part?
If you have automatic updates enabled in Firefox or Thunderbird, the patched versions should install automatically. Check Help > About to verify your current version matches or exceeds the fixed versions (Firefox/Thunderbird 152, or ESR 140.12). If automatic updates are disabled, manual updates must be applied manually through the same menu.
Are other browsers affected?
No. This vulnerability is specific to Mozilla's Firefox and Thunderbird applications. Chrome, Edge, Safari, and other browsers are not affected by this particular boundary condition flaw in Mozilla's CanvasWebGL component.
This analysis is provided for informational purposes to support cybersecurity decision-making. The vulnerability details, affected versions, and patch information are derived from official Mozilla advisories and the National Vulnerability Database. Organizations should verify patch applicability in their specific environment and test updates before broad deployment. No exploit code or weaponized proof-of-concept details are provided herein. Consult vendor advisories and your own risk assessment protocols before prioritization decisions. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-44893HIGHNetty HAProxy Codec Memory Leak Denial of Service
- CVE-2026-10701HIGHFirefox Text Rendering Memory Disclosure Vulnerability
- CVE-2026-11799HIGHUXSS in Mozilla Focus & Klar iOS – Patch to 151.3.1 Now
- CVE-2026-12289HIGHFirefox & Thunderbird WebRender Privilege Escalation (CVSS 8.8)
- CVE-2026-12290HIGHFirefox and Thunderbird Memory Safety Vulnerability – Patch Guidance
- CVE-2026-12291HIGHFirefox & Thunderbird HTTP Use-After-Free RCE (CVSS 8.8)
- CVE-2026-12292HIGHFirefox and Thunderbird Web Audio Boundary Condition Vulnerability (CVSS 8.1)
- CVE-2026-12305HIGHFirefox & Thunderbird Memory Safety Vulnerability (CVSS 7.5)