Impact
The vulnerability resides in the Graphics: WebGPU component and allows an attacker to read data processed or displayed by the browser via WebGPU. The flaw does not enable arbitrary code execution or system file access; it simply exposes sensitive information that may be stored in GPU buffers or transmitted by web content. The issue was addressed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Affected Systems
Mozilla Firefox browsers prior to version 155 and Firefox ESR 153.2, along with Mozilla Thunderbird prior to version 155 and Thunderbird ESR 153.2, are susceptible. Users running older builds of these releases should consider these versions as affected by the flaw.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed in widespread exploitation. The CVSS score of 7.5 indicates a moderate severity risk for information disclosure. It is inferred that an attacker can trigger the vulnerability by serving specially crafted content that engages the WebGPU API while the user’s browser has the feature enabled.
OpenCVE Enrichment