Information disclosure in the Graphics: WebGPU component
Description
Information disclosure in the Graphics: WebGPU component
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Mozilla
PRODUCT: Firefox, Thunderbird
AFFECTED_VERSIONS: Versions prior to 151
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An information disclosure vulnerability exists in the WebGPU graphics component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote attackers to access sensitive data.
Executive Summary:
An information disclosure vulnerability in the WebGPU component of Mozilla Firefox and Thunderbird allows remote attackers to access protected system information.
Vulnerability Details
CVE-ID: CVE-2026-8967
Affected Software: Mozilla Firefox and Thunderbird
Affected Versions: Versions prior to 151
Vulnerability: This vulnerability affects the Graphics: WebGPU component. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates that the flaw is fully automatable and does not require user interaction or authentication to exploit.
Business Impact
Successful exploitation allows unauthorized access to potentially sensitive information processed within the browser's graphics memory. With a CVSS score of 7.5, this vulnerability represents a significant risk to data confidentiality, as it could facilitate the leakage of sensitive user data or system artifacts to external actors.
Remediation Plan
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 151 or later immediately to resolve the memory exposure.
Proactive Monitoring: Review web server and endpoint logs for suspicious requests directed at graphics-intensive web applications.
Compensating Controls: Use network-level filtering to block access to untrusted domains that may attempt to utilize malicious WebGPU calls.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of May 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The lack of required user interaction makes this vulnerability particularly dangerous for automated, wide-scale scanning by remote attackers.
Analyst Recommendation
The severity of this information disclosure necessitates an immediate update. Organizations should ensure all browser instances are updated to version 151 to eliminate the risk of automated data exposure.