Impact
This vulnerability occurs when the WebGPU component in Mozilla products uses uninitialized memory, allowing an attacker to read sensitive data example of CWE 908, resulting in confidentiality loss rather than integrity or availability damage.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird installations that run prior to version 153 are affected; the issue was fixed in Firefox 153 and Thunderbird 153. Any system deploying those earlier releases must be considered vulnerable until the update is applied.
Risk and Exploitability
The CVSS score of 7.5 signals a high‑severity information‑disclosure risk. The EPSS score of less than 1% indicates that real‑world exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious webpage or script that can initiate a WebGPU request from the browser or email client, exploiting the uninitialized memory; however, no exploit code has been observed publicly to date.
OpenCVE Enrichment