CVE-2026-16376

7.5

Mozilla · Firefox

A denial-of-service vulnerability exists in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird prior to version 153.

Executive summary

An unauthenticated remote denial-of-service vulnerability in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird poses a high risk to application availability.

Vulnerability

This denial-of-service vulnerability resides within the Graphics: WebGPU component, allowing unauthenticated attackers with network access to cause service disruptions without requiring user interaction.

Business impact

A successful exploitation of this flaw can result in unexpected application crashes or complete service unavailability for end users, severely impacting operational productivity. With a CVSS score of 7.5, this high-severity rating reflects the ease of remote exploitation over the network without any authentication or user interaction barriers.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 153 or later as specified in the vendor advisories.

Proactive Monitoring: Monitor client endpoints for abnormal browser crash frequencies or recurring application restarts associated with WebGPU processes.

Compensating Controls: Implement network perimeter controls or restrict untrusted web content execution if patching is delayed, though upgrading remains the primary defense.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations must treat this high-severity vulnerability with urgency by deploying the official updates for Firefox and Thunderbird as soon as possible. Prioritizing this update prevents potential denial-of-service conditions across enterprise client environments.

More Mozilla CVEs

Sources

Originally found and disclosed by Mihalis Haatainen, per the CVE Program record.