Impact
A use‑after‑free flaw exists in the WebGPU component of Mozilla Firefox’s graphics subsystem. The vulnerability can corrupt memory when WebGPU resources are released and then accessed, potentially allowing an attacker to execute arbitrary code. The weakness aligns with CWE‑416, which is known to enable crashes or code execution. Based on the description, the primary impact is the ability to compromise the victim system’s confidentiality or integrity via malicious web content that is rendered through WebGPU.
Affected Systems
The flaw affects Mozilla Firefox through version 157 and earlier. The fix is incorporated in Firefox 157 onward. All installations of Firefox that have not yet reached or surpassed this version are potentially vulnerable, regardless of operating system. No further vendor or product details are provided.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploitation at this time. However, the nature of the flaw—use‑after‑free in a web‑enabled graphics component—implies a high severity if exploited, as it could be triggered by a maliciously crafted web page or a compromised resource loaded by WebGPU. The CVSS score is not disclosed, but the risk model suggests that an unpatched client could be used to execute arbitrary code with the privileges of the Firefox process. The attack vector is likely remote, via WebGPU-enabled content delivered through a browser session.
OpenCVE Enrichment