CVE-2026-6773

7.5

Mozilla · Firefox, Thunderbird

An integer overflow in the Graphics: WebGPU component allows unauthenticated remote attackers to trigger a denial of service.

Executive summary

Mozilla Firefox and Thunderbird are vulnerable to a denial of service attack via an integer overflow in the WebGPU component, potentially crashing the application for remote users.

Vulnerability

The vulnerability is an integer overflow flaw located within the Graphics: WebGPU component. It permits an unauthenticated attacker to cause a denial of service by triggering the overflow, which results in application instability or termination.

Business impact

This vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the potential for service disruption. Successful exploitation results in the unexpected termination of the browser or email client, which can disrupt business operations, hinder user productivity, and require manual intervention to restore normal service.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 150 or later to apply the necessary security patches.

Proactive Monitoring: Monitor system logs and crash reporting metrics for an unusual volume of application termination events or service interruptions.

Compensating Controls: While no direct virtual patch exists, maintain standard endpoint protection and ensure that browser-based security policies are enforced to limit exposure to untrusted web content.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this vulnerability, combined with the ease of exploitation via the WebGPU component, necessitates prompt action. IT administrators should prioritize the deployment of Firefox and Thunderbird updates to version 150 across all enterprise endpoints to eliminate the risk of service disruption.

More Mozilla CVEs

Sources

Originally found and disclosed by Richard Belisle, per the CVE Program record.