Junglewise Threat Intelligence

CVE-2026-16384: Mozilla Firefox information disclosure in WebGPU component

CVE-2026-16384 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a widely used web browser. A vulnerability in its WebGPU graphics component could allow a malicious website to access sensitive information from the computer's memory that it should not be able to see. This could potentially expose private data from other browser tabs or system processes.

Technical details

An information disclosure vulnerability exists in the Graphics: WebGPU component of Mozilla Firefox. The flaw is caused by the use of uninitialized memory, which can be leveraged by a remote attacker to leak sensitive information from the process memory. The vulnerability is triggered when a user visits a specially crafted website that interacts with the WebGPU API. This issue was addressed in Firefox version 153 by ensuring proper initialization of memory buffers.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory
  • 2026-07-21: patched: Fixed in Firefox 153

References

Related threats