Description
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs when the WebGPU component in Mozilla products uses uninitialized memory, allowing an attacker to read sensitive data example of CWE 908, resulting in confidentiality loss rather than integrity or availability damage.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird installations that run prior to version 153 are affected; the issue was fixed in Firefox 153 and Thunderbird 153. Any system deploying those earlier releases must be considered vulnerable until the update is applied.

Risk and Exploitability

The CVSS score of 7.5 signals a high‑severity information‑disclosure risk. The EPSS score of less than 1% indicates that real‑world exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious webpage or script that can initiate a WebGPU request from the browser or email client, exploiting the uninitialized memory; however, no exploit code has been observed publicly to date.

Generated by OpenCVE AI on August 3, 2026 at 00:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 153 or newer.
  • Upgrade Mozilla Thunderbird to version 153 or newer.
  • If an update cannot be applied immediately, disable WebGPU in.enabled to false to eliminate the risk until the patch is installed.

Generated by OpenCVE AI on August 3, 2026 at 00:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
Title Information disclosure due to uninitialized memory in the Graphics: WebGPU component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:49.862Z

Reserved: 2026-07-20T21:57:02.260Z

Link: CVE-2026-16386

cve-icon Vulnrichment

Updated: 2026-07-22T17:14:38.146Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:13.763

Modified: 2026-07-27T13:47:54.970

Link: CVE-2026-16386

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:00Z

Links: CVE-2026-16386 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer

  • CWE-908

    Use of Uninitialized Resource