CVE-2026-16376
7.5Mozilla · Firefox
A denial-of-service vulnerability exists in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird prior to version 153.
Executive summary
An unauthenticated remote denial-of-service vulnerability in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird poses a high risk to application availability.
Vulnerability
This denial-of-service vulnerability resides within the Graphics: WebGPU component, allowing unauthenticated attackers with network access to cause service disruptions without requiring user interaction.
Business impact
A successful exploitation of this flaw can result in unexpected application crashes or complete service unavailability for end users, severely impacting operational productivity. With a CVSS score of 7.5, this high-severity rating reflects the ease of remote exploitation over the network without any authentication or user interaction barriers.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 153 or later as specified in the vendor advisories.
Proactive Monitoring: Monitor client endpoints for abnormal browser crash frequencies or recurring application restarts associated with WebGPU processes.
Compensating Controls: Implement network perimeter controls or restrict untrusted web content execution if patching is delayed, though upgrading remains the primary defense.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations must treat this high-severity vulnerability with urgency by deploying the official updates for Firefox and Thunderbird as soon as possible. Prioritizing this update prevents potential denial-of-service conditions across enterprise client environments.
More Mozilla CVEs
Sources
Originally found and disclosed by Mihalis Haatainen, per the CVE Program record.