Description
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Incorrect boundary conditions were discovered in Mozilla's WebGPU component. The flaw occurs when WebGPU processes inputs that exceed the allocated bounds for internal data structures, leading to memory corruption. The CVE does not state specific consequences, but memory corruption can result in application crashes or corrupted state.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected in any release older than version 153. Versions 153 and later include the fix, so only installations preceding that version are vulnerable.

Risk and Exploitability

The CVSS score of 9.1 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not defined in the description, but it is inferred that malicious content invoking WebGPU in a browser or email client could trigger the boundary condition error, potentially leading to denial of service or other memory corruption effects.

Generated by OpenCVE AI on August 3, 2026 at 00:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 153 or later.
  • Upgrade Mozilla Thunderbird to version 153 or later.
  • Keep the browser and email client updated by checking the vendor's security advisories and applying patches promptly.

Generated by OpenCVE AI on August 3, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153. Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153.
Title Incorrect boundary conditions in the Graphics: WebGPU component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:57.465Z

Reserved: 2026-07-20T21:57:17.403Z

Link: CVE-2026-16393

cve-icon Vulnrichment

Updated: 2026-07-22T17:20:53.555Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:14.500

Modified: 2026-07-24T16:42:08.643

Link: CVE-2026-16393

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:06Z

Links: CVE-2026-16393 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read