Junglewise Threat Intelligence

CVE-2026-12293: Mozilla Firefox use-after-free in WebGPU component

CVE-2026-12293 · Severity: info · CVSS 8.8 · Published 2026-06-16

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability exists in the WebGPU component of the Firefox web browser, which is used for high-performance graphics processing. If a user visits a malicious website, an attacker could exploit this flaw to crash the browser or potentially execute unauthorized code on the user's computer. This could lead to the theft of sensitive data or a full compromise of the user's local system.

Technical details

A use-after-free vulnerability exists in the Graphics: WebGPU component of Mozilla Firefox. The flaw occurs when the browser continues to use a memory address after it has been freed, leading to memory corruption. An attacker can exploit this by enticing a user to visit a specially crafted webpage, potentially achieving arbitrary code execution within the context of the browser process. This vulnerability was addressed in Firefox 152 by improving memory management within the WebGPU implementation.

Affected products

  • Mozilla Firefox < 152

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched: Fixed in Firefox 152

References

Related threats