Junglewise Threat Intelligence

CVE-2026-5733: Mozilla Firefox and Thunderbird out-of-bounds write in WebGPU

CVE-2026-5733 · Severity: high · CVSS 8.8 · Published 2026-04-07

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the WebGPU component of Mozilla Firefox and Thunderbird, which are used for web browsing and email communication. An attacker could exploit this flaw to potentially gain unauthorized access to data or disrupt the application's stability. Users are advised to update to version 149.0.2 or later to mitigate this risk.

Technical details

This vulnerability is classified as an out-of-bounds write (CWE-787) or improper restriction of operations within memory buffer bounds (CWE-119) within the Graphics: WebGPU component of Mozilla products. The flaw is triggered by incorrect boundary conditions during the processing of WebGPU content. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted webpage or interact with malicious content in a browser-like context, potentially leading to arbitrary code execution or a denial-of-service (memory corruption). The issue is resolved in Firefox 149.0.2 and Thunderbird 149.0.2.

Affected products

  • Mozilla Firefox < 149.0.2
  • Mozilla Thunderbird < 149.0.2

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: patched
  • 2026-04-07: advisory

References

Related threats