Impact
Denial-of-service vulnerability in the Graphics: WebGPU component causes uncontrolled resource allocation, which can lead to a crash or unresponsive state, thereby denying service to the user. The flaw was fixed in Firefox 153 and Thunderbird 153.
Affected Systems
Mozilla Firefox browsers and Thunderbird email clients prior to version 153 are affected. Users running any release older than 153 should consider themselves vulnerable. No specific sub-versions are listed, but all builds before the 153 release are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact, while the EPSS score (<1%) shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a remote attacker could trigger the flaw by delivering malicious WebGPU content through a web page or script, leading to resource exhaustion and a crash.
OpenCVE Enrichment