Impact
This flaw is a use‑after‑free bug in the WebGPU graphics component of Firefox. An attacker can trigger the bug to run code with the same privileges as the currently running process, potentially enabling arbitrary code execution and privilege escalation on the affected system. The weakness conforms to the standard definition of Use‑After‑Free (CWE‑416).
Affected Systems
The vulnerability affects all versions of Mozilla Firefox released before the security fixes in Firefox 155 and Firefox ESR 153.2. Users running these earlier releases are at risk, regardless of the operating system or hardware platform. No other vendors or products are listed as affected.
Risk and Exploitability
Because the bug permits code execution with elevated privileges, the impact is high. The likely attack vector is through malicious web content that loads WebGPU resources or triggers graphics processing in the Firefox browser, requiring an attacker to host or provide a page that the user visits. Exploitation conditions inferred from the description indicate that the attack would need to target a rendering context within Firefox's WebGPU component, so any user who loads such content could be affected. The official CVSS score is not provided in the data, and the EPSS score is unavailable, so the exploitation probability cannot be quantified from this information. The flaw is not reported in the CISA KEV catalog, indicating no known public exploitation at the time of this report.
OpenCVE Enrichment