Description
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
Published: 2025-11-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Apply patch
AI Analysis

Impact

Incorrect boundary conditions in the WebGPU component of Mozilla's graphics engine can lead to memory corruption or out‑of‑bounds memory access. The vulnerability is classified under CWE-805 and CWE-276, indicating potential buffer errors and permission or access control issues, and is rated with a CVSS score of 7.5. The impact could compromise data confidentiality, integrity, or availability of the affected system, but the description does not explicitly state arbitrary code execution.

Affected Systems

Affected software includes Mozilla Firefox and Mozilla Thunderbird. The issue exists in all releases prior to version 145 for both products. The official fix was introduced in Firefox 145 and Thunderbird 145, restoring proper bounds checking and permission policies.

Risk and Exploitability

The EPSS score of less than 1% indicates that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The CVSS rating of 7.5 suggests a high potential impact should the flaw be successfully triggered, but the actual risk depends on the ability to invoke WebGPU from malicious sources. Based on the description, it is inferred that the attack vector could involve malicious web content that activates WebGPU, potentially triggering the memory corruption. Monitoring for exploitation is advised, but the low exploitation probability and absence from KEV reduce immediate risk.

Generated by OpenCVE AI on April 20, 2026 at 19:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 145 or newer and Mozilla Thunderbird 145 or newer.
  • Disable WebGPU by setting dom.webgpu.enabled to false in about:config until the patch is applied.
  • Check Mozilla security advisories regularly to apply future updates.

Generated by OpenCVE AI on April 20, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145. Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Wed, 19 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145. Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
References

Mon, 17 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*

Wed, 12 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Wed, 12 Nov 2025 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Tue, 11 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145.
Title Incorrect boundary conditions in the Graphics: WebGPU component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:26:24.598Z

Reserved: 2025-11-11T15:12:34.232Z

Link: CVE-2025-13025

cve-icon Vulnrichment

Updated: 2025-11-12T15:23:59.458Z

cve-icon NVD

Status : Modified

Published: 2025-11-11T16:15:39.613

Modified: 2026-04-13T15:16:44.300

Link: CVE-2025-13025

cve-icon Redhat

Severity : Important

Publid Date: 2025-11-11T15:47:15Z

Links: CVE-2025-13025 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T19:15:15Z

Weaknesses