CVE-2025-49709Critical· 9.8▾ MidnightCertain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.
firefox < 139.0.4Upgrade past the affected range:
firefox 139.0.4Connected by shared product, vendor, weakness, or advisory.
CVE-2023-29551High· 8.8Memory safety bugs present in Firefox 111
CVE-2026-8092High· 8.1Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1
CVE-2026-92007High· 8.8Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-92008High· 8.8Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-92013High· 8.8Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-92009High· 8.8Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component