Impact
This vulnerability lies within the Graphics: WebGPU component of Mozilla Firefox, allowing an attacker to exfiltrate information that the browser processes or displays. The disclosed flaw does not provide control over system files or code execution, but it can leak sensitive data handled by the WebGPU API. As an information‑exposure issue, the primary consequence is the potential compromise of user confidentiality and privacy, especially when malicious web content is loaded while the component is active.
Affected Systems
Mozilla Firefox browsers prior to version 155 and Firefox ESR prior to 153.2 are susceptible. Users running older builds of these releases should consider these versions as affected by the flaw.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed in widespread exploitation. The CVSS score is not provided, but the nature of the issue—information disclosure via WebGPU—suggests a moderate to high impact when executed. It is inferred that an attacker can trigger the vulnerability by serving specially crafted content that engages the WebGPU API while the user’s browser has the feature enabled.
OpenCVE Enrichment