Junglewise Threat Intelligence

CVE-2026-16393: Mozilla Firefox incorrect boundary conditions in WebGPU

CVE-2026-16393 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the WebGPU graphics component of the Firefox web browser. This component is responsible for allowing web applications to use the computer's graphics hardware for high-performance tasks. An exploit could potentially lead to browser instability or unauthorized access to memory, though it is mitigated by the browser's security sandbox.

Technical details

Mozilla Firefox versions prior to 153 are affected by an incorrect boundary conditions vulnerability within the Graphics: WebGPU component. The flaw is triggered when processing WebGPU commands, potentially leading to out-of-bounds memory access. While the advisory classifies the impact as 'moderate,' such boundary condition errors typically allow for information disclosure or denial-of-service within the content process. Exploitation would likely require a user to visit a specially crafted website. The vulnerability is resolved in Firefox 153.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched: Fixed in Firefox 153

References

Related threats