Executive brief
Firefox's WebGPU graphics component contains a vulnerability that could allow an attacker to disclose sensitive memory information. WebGPU is a modern graphics API used for accelerated rendering in web browsers. This vulnerability could expose private data from the browser or system memory to an attacker, potentially compromising user privacy or security.
Technical details
CVE-2026-84130 is an information disclosure vulnerability in the Graphics: WebGPU component of Firefox. The vulnerability allows an attacker to read sensitive data from memory, likely through a crafted WebGPU shader or graphics operation that exploits improper bounds checking or access controls. The vulnerability is remotely exploitable through a malicious web page without requiring user authentication or local access. The attack vector is network-based, leveraging the user's browser's graphics rendering capabilities. The vulnerability has been patched in Firefox 155, Firefox ESR 153.2, and corresponding Thunderbird releases.
Affected products
- Mozilla Firefox before 155
- Mozilla Firefox ESR before 153.2
- Mozilla Thunderbird before 155
- Mozilla Thunderbird before 153.2
Timeline
- 2026-09-01: disclosed: Published in Mozilla Security Advisory MFSA2026-82
- 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, Thunderbird 153.2