Description
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
Published: 2026-09-29
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information disclosure
Action: Upgrade Firefox
AI Analysis

Impact

Uninitialized memory was discovered in the Graphics: WebGPU component of Mozilla Firefox. The flaw allows the use of data that has not been properly initialized, potentially exposing sensitive information that resides in memory. Depending on the context in which the uninitialized data is accessed, an attacker could read arbitrary data or, in the worst case, execute arbitrary code through memory misuse.

Affected Systems

The vulnerability affects all releases of Mozilla Firefox prior to version 157. Users of Firefox 156 or earlier are potentially exposed, while versions 157 and later contain the fix.

Risk and Exploitability

The flaw was assigned a high severity, but the exact CVSS score is not available. The EPSS for this issue is not reported, and it is not listed in the CISA KEV catalog. Because the WebGPU API is exposed to web content, a malicious website could trigger the uninitialized memory usage via JavaScript, making the attack vector likely remote from web traffic. However, exploitation may also be possible locally if a user runs privileged code or shares a sandboxed process with the browser. The vulnerability exists as a result of an improperly initialized internal state in the WebGPU driver component.

Generated by OpenCVE AI on September 29, 2026 at 16:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox 157 or later
  • Disable the WebGPU feature by setting 'dom.webgpu.enabled' to false in about:config
  • Keep Firefox updated and follow Mozilla security advisories

Generated by OpenCVE AI on September 29, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
Title Uninitialized memory in the Graphics: WebGPU component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T16:30:00.876Z

Reserved: 2026-09-26T19:17:48.744Z

Link: CVE-2026-100802

cve-icon Vulnrichment

Updated: 2026-09-29T16:27:05.671Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:45.287

Modified: 2026-09-29T17:17:04.607

Link: CVE-2026-100802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:30:18Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable

  • CWE-788

    Access of Memory Location After End of Buffer