Description
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw is a use‑after‑free bug in the WebGPU graphics component of Firefox. An attacker can trigger the bug to run code with the same privileges as the currently running process, potentially enabling arbitrary code execution and privilege escalation on the affected system. The weakness conforms to the standard definition of Use‑After‑Free (CWE‑416).

Affected Systems

The vulnerability affects all versions of Mozilla Firefox released before the security fixes in Firefox 155 and Firefox ESR 153.2. Users running these earlier releases are at risk, regardless of the operating system or hardware platform. No other vendors or products are listed as affected.

Risk and Exploitability

Because the bug permits code execution with elevated privileges, the impact is high. The likely attack vector is through malicious web content that loads WebGPU resources or triggers graphics processing in the Firefox browser, requiring an attacker to host or provide a page that the user visits. Exploitation conditions inferred from the description indicate that the attack would need to target a rendering context within Firefox's WebGPU component, so any user who loads such content could be affected. The official CVSS score is not provided in the data, and the EPSS score is unavailable, so the exploitation probability cannot be quantified from this information. The flaw is not reported in the CISA KEV catalog, indicating no known public exploitation at the time of this report.

Generated by OpenCVE AI on September 1, 2026 at 13:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or later, or to Firefox ESR 153.2 or later.
  • If an update cannot be applied immediately, disable WebGPU by setting the about:config preference browser.webgpu.enabled to false as a temporary mitigation.
  • Stay alert for further security advisories and apply subsequent fixes as they become available.

Generated by OpenCVE AI on September 1, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Privilege escalation due to use-after-free in the Graphics: WebGPU component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T14:16:54.226Z

Reserved: 2026-09-01T07:25:15.751Z

Link: CVE-2026-84123

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:06.160

Modified: 2026-09-01T13:20:06.160

Link: CVE-2026-84123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:04Z

Weaknesses