Junglewise Threat Intelligence

CVE-2026-8967: Mozilla Firefox information disclosure in WebGPU component

CVE-2026-8967 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability in the WebGPU graphics component of the Firefox web browser could allow a malicious website to access information it should not be able to see. This could potentially lead to the disclosure of sensitive data from the user's browsing session. Users are advised to update to Firefox 151 or later to resolve this issue.

Technical details

An information disclosure vulnerability exists in the Graphics: WebGPU component of Mozilla Firefox. While specific technical details regarding the root cause (such as the specific memory or logic error) are restricted in the associated Bugzilla report, the flaw allows for the unauthorized retrieval of information through the WebGPU API. The vulnerability is reachable via malicious web content and does not require user interaction beyond visiting a site. The issue is resolved in Firefox 151.

Affected products

  • Mozilla Firefox < 151

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats