Junglewise Threat Intelligence

CVE-2026-16386: Mozilla Firefox information disclosure in WebGPU

CVE-2026-16386 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used for accessing the internet. A security vulnerability in the WebGPU component, which handles high-performance graphics, could allow a malicious website to access sensitive information from the computer's memory. This could potentially expose private data from other browser tabs or applications to an attacker.

Technical details

An information disclosure vulnerability exists in the WebGPU component of Mozilla Firefox. The flaw is caused by the use of uninitialized memory, which can lead to the leakage of sensitive data from the process memory. An attacker could exploit this by tricking a user into visiting a specially crafted website that utilizes WebGPU features. This vulnerability was addressed in Firefox version 153 by ensuring proper memory initialization.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: disclosed
  • 2026-07-21: patched

References

Related threats