Impact
The flaw originates from uninitialized memory usage in the Graphics: WebGPU component API calls. The documented weakness is classified as CWE-908 and CWE-824 and carries a CVSS score of 7.5, indicating a substantial risk to confidentiality if exploited.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird running versions prior to 153 are affected. Users on these older releases may be exposed until they upgrade to the patched versions.
Risk and Exploitability
Although the CVSS score signals a high severity, the EPSS score of less than 1% indicates a low exploitation probability. The vulnerability is not listed in CISA's KEV catalog. The attack vector would presumably involve a web page or extension that enables WebGPU, requiring the ability to run additional graphics code; this is typically available to any site that can execute JavaScript.
OpenCVE Enrichment