Impact
Uninitialized memory was discovered in the Graphics: WebGPU component of Mozilla Firefox. The flaw allows the use of data that has not been properly initialized, potentially exposing sensitive information that resides in memory. Depending on the context in which the uninitialized data is accessed, an attacker could read arbitrary data or, in the worst case, execute arbitrary code through memory misuse.
Affected Systems
The vulnerability affects all releases of Mozilla Firefox prior to version 157. Users of Firefox 156 or earlier are potentially exposed, while versions 157 and later contain the fix.
Risk and Exploitability
The flaw was assigned a high severity, but the exact CVSS score is not available. The EPSS for this issue is not reported, and it is not listed in the CISA KEV catalog. Because the WebGPU API is exposed to web content, a malicious website could trigger the uninitialized memory usage via JavaScript, making the attack vector likely remote from web traffic. However, exploitation may also be possible locally if a user runs privileged code or shares a sandboxed process with the browser. The vulnerability exists as a result of an improperly initialized internal state in the WebGPU driver component.
OpenCVE Enrichment