Junglewise Threat Intelligence

CVE-2026-12303: Mozilla Firefox information disclosure in WebGPU component

CVE-2026-12303 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used for accessing the internet. A security flaw in its WebGPU graphics component could allow a malicious website to access information it should not be able to see. This could lead to the disclosure of sensitive data from the user's browsing session or system.

Technical details

An information disclosure vulnerability exists in Mozilla Firefox's WebGPU component due to incorrect boundary conditions. The flaw allows for out-of-bounds access or similar boundary-related errors within the graphics processing logic. An attacker can exploit this by enticing a user to visit a specially crafted website, potentially leading to the leakage of sensitive memory contents or other protected information. The issue is resolved in Firefox version 152.

Affected products

  • Mozilla Firefox < 152

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched

References

Related threats