Description
Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
Published: 2026-09-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Update Browser
AI Analysis

Impact

This flaw allows an attacker to gain elevated privileges by exploiting erroneous boundary checks within the Graphics WebGPU subsystem. The incorrect checks can lead to uncontrolled memory accesses, potentially enabling the execution of arbitrary code or local privilege escalation. The weakness falls under improper calculation of memory bounds and can compromise confidentiality, integrity, or availability of the affected system. The primary impact is the ability to run code with higher privileges than intended for resource handling.

Affected Systems

Mozilla Firefox browsers older than version 157 are affected. Intermediate updates prior to version 157 do not contain the fix. Users running Firefox 156 or earlier are at risk.

Risk and Exploitability

Because no sample exploits are publicly documented, the known exploitation probability is unknown, but the vulnerability can be leveraged by any entity capable of influencing WebGPU calls, including local applications or malicious web content. The lack of an EPSS score and exclusion from the CISA KEV catalog suggest that the likelihood of widespread exploitation is currently uncertain, yet the severity of the potential impact is high due to the privilege‑escalation nature of the flaw. An attacker who can invoke WebGPU operations from within a user‑level context could bypass browser sandbox restrictions and gain uncontrolled access to system resources.

Generated by OpenCVE AI on September 29, 2026 at 14:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox version 157 or later, which contains the patch for the boundary condition checks.
  • If an immediate upgrade is infeasible, disable WebGPU by setting the preference dom.webgpu.enabled to false in Firefox’s configuration to prevent WebGPU calls from executing.
  • Apply the above measures on all systems that use MacOS or Windows versions of Firefox with the affected software stack to reduce the attack surface.

Generated by OpenCVE AI on September 29, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
Title Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T13:14:33.006Z

Reserved: 2026-09-26T19:15:20.971Z

Link: CVE-2026-100764

cve-icon Vulnrichment

Updated: 2026-09-29T13:14:15.579Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:40.640

Modified: 2026-09-29T14:17:16.730

Link: CVE-2026-100764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:45:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer