Impact
The vulnerability is a flaw in the Graphics: WebGPU component that permits the use of memory that has not been initialized. This can lead to the exposure of sensitive data that resides in the affected memory region or to program instability. The weakness is a classic example of improper initialization, which is known to allow data leakage or crashes, but the description does not state a proven exploitation path or impact beyond these possibilities.
Affected Systems
Mozilla Firefox is affected in all builds prior to version 157, where the WebGPU component was patched. Users running Firefox 157 or later are not subject to this defect.
Risk and Exploitability
The CVE does not provide a CVSS score and the EPSS assessment is not available, so the precision of the risk estimate is limited. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers would likely need to deliver malicious web content that activates WebGPU in a context where the uninitialized memory can be accessed, implying a local or privileged web‑content vector. Because the details of exploitation are not documented, the likelihood of remote exploitation is considered low, but the absence of a public CVSS score and EPSS data should encourage cautious monitoring.
OpenCVE Enrichment