Executive brief
Mozilla Firefox was found to have a security vulnerability in its WebGPU graphics component. This flaw could allow a malicious website to access sensitive information from the computer's memory that it should not be able to see. This could potentially lead to the exposure of private data or help an attacker bypass other security protections. Users should update to Firefox 153 or later to resolve this issue.
Technical details
An information disclosure vulnerability exists in the WebGPU component of Mozilla Firefox. The flaw is caused by the use of uninitialized memory, which can lead to the exposure of sensitive data from the process memory to a malicious web page. An attacker could exploit this by enticing a user to visit a specially crafted website. This vulnerability was addressed in Firefox 153 by ensuring proper initialization of memory buffers within the Graphics: WebGPU component.
Affected products
- Mozilla Firefox < 153
Timeline
- 2026-07-21: advisory: Mozilla Foundation Security Advisory 2026-68 published
- 2026-07-21: patched: Fixed in Firefox 153