Description
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability lies within the Graphics: WebGPU component of Mozilla Firefox, allowing an attacker to exfiltrate information that the browser processes or displays. The disclosed flaw does not provide control over system files or code execution, but it can leak sensitive data handled by the WebGPU API. As an information‑exposure issue, the primary consequence is the potential compromise of user confidentiality and privacy, especially when malicious web content is loaded while the component is active.

Affected Systems

Mozilla Firefox browsers prior to version 155 and Firefox ESR prior to 153.2 are susceptible. Users running older builds of these releases should consider these versions as affected by the flaw.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed in widespread exploitation. The CVSS score is not provided, but the nature of the issue—information disclosure via WebGPU—suggests a moderate to high impact when executed. It is inferred that an attacker can trigger the vulnerability by serving specially crafted content that engages the WebGPU API while the user’s browser has the feature enabled.

Generated by OpenCVE AI on September 1, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or Firefox ESR 153.2 where the flaw is mitigated
  • If immediate upgrade is not possible, disable the WebGPU feature by setting dom.webgpu.enabled to false in about:config
  • Continue monitoring for relevant security advisories and apply subsequent patches as they become available

Generated by OpenCVE AI on September 1, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Information disclosure in the Graphics: WebGPU component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:18:57.806Z

Reserved: 2026-09-01T07:25:31.624Z

Link: CVE-2026-84130

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:07.013

Modified: 2026-09-01T13:20:07.013

Link: CVE-2026-84130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor