Impact
Incorrect boundary conditions were discovered in Mozilla's WebGPU component. The flaw occurs when WebGPU processes inputs that exceed the allocated bounds for internal data structures, leading to memory corruption. The CVE does not state specific consequences, but memory corruption can result in application crashes or corrupted state.
Affected Systems
Mozilla Firefox and Mozilla Thunderbird are affected in any release older than version 153. Versions 153 and later include the fix, so only installations preceding that version are vulnerable.
Risk and Exploitability
The CVSS score of 9.1 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not defined in the description, but it is inferred that malicious content invoking WebGPU in a browser or email client could trigger the boundary condition error, potentially leading to denial of service or other memory corruption effects.
OpenCVE Enrichment