Description
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Published: 2026-09-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Graphics: WebGPU component and allows an attacker to read data processed or displayed by the browser via WebGPU. The flaw does not enable arbitrary code execution or system file access; it simply exposes sensitive information that may be stored in GPU buffers or transmitted by web content. The issue was addressed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Affected Systems

Mozilla Firefox browsers prior to version 155 and Firefox ESR 153.2, along with Mozilla Thunderbird prior to version 155 and Thunderbird ESR 153.2, are susceptible. Users running older builds of these releases should consider these versions as affected by the flaw.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed in widespread exploitation. The CVSS score of 7.5 indicates a moderate severity risk for information disclosure. It is inferred that an attacker can trigger the vulnerability by serving specially crafted content that engages the WebGPU API while the user’s browser has the feature enabled.

Generated by OpenCVE AI on September 3, 2026 at 20:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or Firefox ESR 153.2 where the flaw is mitigated
  • Upgrade Thunderbird to version 155 or Thunderbird 153.2 where the flaw is mitigated
  • If immediate upgrade is not possible, disable the WebGPU feature by setting dom.webgpu.enabled to false in about:config
  • Continue monitoring for relevant security advisories and apply subsequent patches as they become available

Generated by OpenCVE AI on September 3, 2026 at 20:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 02 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2. Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
References

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Information disclosure in the Graphics: WebGPU component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-03T17:24:42.674Z

Reserved: 2026-09-01T07:25:31.624Z

Link: CVE-2026-84130

cve-icon Vulnrichment

Updated: 2026-09-03T15:43:12.296Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T13:20:07.013

Modified: 2026-09-03T18:35:38.103

Link: CVE-2026-84130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor