Description
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Denial-of-service vulnerability in the Graphics: WebGPU component causes uncontrolled resource allocation, which can lead to a crash or unresponsive state, thereby denying service to the user. The flaw was fixed in Firefox 153 and Thunderbird 153.

Affected Systems

Mozilla Firefox browsers and Thunderbird email clients prior to version 153 are affected. Users running any release older than 153 should consider themselves vulnerable. No specific sub-versions are listed, but all builds before the 153 release are impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact, while the EPSS score (<1%) shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a remote attacker could trigger the flaw by delivering malicious WebGPU content through a web page or script, leading to resource exhaustion and a crash.

Generated by OpenCVE AI on August 3, 2026 at 00:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 153 or later or Thunderbird 153 or later to apply the vendor fix.
  • Disable WebGPU by setting the preference gfx.webrender.webgpu.enabled to false in the configuration to mitigate the risk if an upgrade cannot be performed immediately.
  • Verify that no untrusted web content accesses WebGPU, and restrict or monitor such content through network firewalls or content filters when possible.

Generated by OpenCVE AI on August 3, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
Title Denial-of-service in the Graphics: WebGPU component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:38.107Z

Reserved: 2026-07-20T21:56:40.610Z

Link: CVE-2026-16376

cve-icon Vulnrichment

Updated: 2026-07-22T15:51:44.292Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:12.760

Modified: 2026-07-24T16:38:54.823

Link: CVE-2026-16376

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:51Z

Links: CVE-2026-16376 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling