Description
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
Published: 2026-09-29
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Update
AI Analysis

Impact

The vulnerability is a flaw in the Graphics: WebGPU component that permits the use of memory that has not been initialized. This can lead to the exposure of sensitive data that resides in the affected memory region or to program instability. The weakness is a classic example of improper initialization, which is known to allow data leakage or crashes, but the description does not state a proven exploitation path or impact beyond these possibilities.

Affected Systems

Mozilla Firefox is affected in all builds prior to version 157, where the WebGPU component was patched. Users running Firefox 157 or later are not subject to this defect.

Risk and Exploitability

The CVE does not provide a CVSS score and the EPSS assessment is not available, so the precision of the risk estimate is limited. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers would likely need to deliver malicious web content that activates WebGPU in a context where the uninitialized memory can be accessed, implying a local or privileged web‑content vector. Because the details of exploitation are not documented, the likelihood of remote exploitation is considered low, but the absence of a public CVSS score and EPSS data should encourage cautious monitoring.

Generated by OpenCVE AI on September 29, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 157 or newer
  • If an immediate upgrade is not feasible, disable the WebGPU API by setting dom.webgpu.enabled to false in about:config or through enterprise policy
  • Continuously monitor Mozilla security advisories and apply updates promptly, and consider restricting access to untrusted web content to mitigate potential exploitation

Generated by OpenCVE AI on September 29, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
Title Uninitialized memory in the Graphics: WebGPU component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T16:30:01.025Z

Reserved: 2026-09-26T19:17:40.901Z

Link: CVE-2026-100799

cve-icon Vulnrichment

Updated: 2026-09-29T16:27:07.305Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:44.973

Modified: 2026-09-29T17:17:04.400

Link: CVE-2026-100799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:00:18Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable

  • CWE-665

    Improper Initialization