CVE-2026-5733

8.8

Mozilla · Firefox, Thunderbird

A boundary condition error in the WebGPU graphics component allows for potential remote code execution or system instability in Mozilla Firefox and Thunderbird.

Executive summary

A critical boundary condition vulnerability in the WebGPU component of Mozilla Firefox and Thunderbird exposes users to potential remote code execution and system compromise.

Vulnerability

This vulnerability involves incorrect boundary conditions within the WebGPU graphics subsystem. It is a remotely exploitable flaw that requires user interaction and does not require prior authentication to trigger.

Business impact

The exploitation of this flaw can lead to a total compromise of the host system, including unauthorized data access and potential system instability. Given the CVSS score of 8.8, this vulnerability represents a high risk to organizational security, particularly for workstations where these browsers are primary interfaces for business operations.

Remediation

Immediate Action: Update both Mozilla Firefox and Mozilla Thunderbird to version 149.0.2 or later to apply the necessary security patches.

Proactive Monitoring: Review endpoint security logs for unusual process execution patterns or unexpected browser crashes that may indicate attempts to exploit graphics components.

Compensating Controls: While browser-based vulnerabilities are difficult to block via network controls, ensuring that the principle of least privilege is applied to user accounts can limit the potential damage if the application is compromised.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.

Analyst recommendation

This vulnerability presents a significant risk to end-user systems due to the potential for code execution via the WebGPU component. Organizations should prioritize the deployment of the 149.0.2 update across all managed instances of Firefox and Thunderbird immediately to mitigate the risk of exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Inseo An, per the CVE Program record.