Executive brief
Mozilla Firefox is a popular web browser used for accessing the internet. A security vulnerability in the WebGPU component, which handles high-performance graphics, could allow a malicious website to access sensitive information from the computer's memory. This could potentially expose private data from other browser tabs or applications to an attacker.
Technical details
An information disclosure vulnerability exists in the WebGPU component of Mozilla Firefox. The flaw is caused by the use of uninitialized memory, which can lead to the leakage of sensitive data from the process memory. An attacker could exploit this by tricking a user into visiting a specially crafted website that utilizes WebGPU features. This vulnerability was addressed in Firefox version 153 by ensuring proper memory initialization.
Affected products
- Mozilla Firefox < 153
Timeline
- 2026-07-21: advisory
- 2026-07-21: disclosed
- 2026-07-21: patched