CVE-2026-16384

7.5

Mozilla · Firefox and Thunderbird

Information disclosure vulnerability in the Graphics: WebGPU component due to uninitialized memory, allowing remote unauthenticated attackers to read sensitive data.

Executive summary

An information disclosure vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to access sensitive memory via the WebGPU component, carrying a high risk of data confidentiality loss.

Vulnerability

This is an information disclosure vulnerability caused by uninitialized memory handling in the Graphics: WebGPU component, which can be triggered by unauthenticated remote attackers over the network without requiring user interaction.

Business impact

The exposure of uninitialized memory can lead to the unauthorized disclosure of sensitive data processed by the browser or email client, potentially leaking session tokens, credentials, or internal application states. With a CVSS score of 7.5, the severity is classified as high due to the network attack vector and the lack of required user interaction or privileges, presenting a significant risk to organizational data confidentiality.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 153 or later where the vulnerability is resolved.

Proactive Monitoring: Monitor network traffic and endpoint telemetry for anomalous application behavior or unexpected crashes related to browser and email client rendering processes.

Compensating Controls: Restrict unnecessary network access and enforce strict endpoint security policies to limit the potential blast radius of compromised client applications.

Exploitation status

Public Exploit Available: No - there is no confirmed public exploit available in the available data.

Analyst recommendation

Organizations must treat this high-severity advisory with appropriate urgency to protect sensitive user and corporate data from potential exposure. IT administrators should deploy the patched software versions across all client endpoints immediately to mitigate the risk of unauthorized information disclosure.

More Mozilla CVEs

Sources

Originally found and disclosed by 5up3rh3i, per the CVE Program record.