Impact
This flaw allows an attacker to gain elevated privileges by exploiting erroneous boundary checks within the Graphics WebGPU subsystem. The incorrect checks can lead to uncontrolled memory accesses, potentially enabling the execution of arbitrary code or local privilege escalation. The weakness falls under improper calculation of memory bounds and can compromise confidentiality, integrity, or availability of the affected system. The primary impact is the ability to run code with higher privileges than intended for resource handling.
Affected Systems
Mozilla Firefox browsers older than version 157 are affected. Intermediate updates prior to version 157 do not contain the fix. Users running Firefox 156 or earlier are at risk.
Risk and Exploitability
Because no sample exploits are publicly documented, the known exploitation probability is unknown, but the vulnerability can be leveraged by any entity capable of influencing WebGPU calls, including local applications or malicious web content. The lack of an EPSS score and exclusion from the CISA KEV catalog suggest that the likelihood of widespread exploitation is currently uncertain, yet the severity of the potential impact is high due to the privilege‑escalation nature of the flaw. An attacker who can invoke WebGPU operations from within a user‑level context could bypass browser sandbox restrictions and gain uncontrolled access to system resources.
OpenCVE Enrichment