CVE-2026-84130
7.5Mozilla · Firefox and Thunderbird
A vulnerability in the WebGPU component of Mozilla Firefox and Thunderbird allows for unauthorized information disclosure.
Executive summary
A high-severity information disclosure vulnerability in the WebGPU component of Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to access sensitive data.
Vulnerability
This flaw exists within the Graphics: WebGPU component of the application. It allows an unauthenticated, remote attacker to bypass security controls and access sensitive information without user interaction.
Business impact
The successful exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive data processed within the browser or email client. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to data confidentiality and organizational privacy. Failure to remediate may result in the compromise of user sessions or private data stored within the affected applications.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 155, or version 153.2 for those utilizing the Extended Support Release (ESR) channel.
Proactive Monitoring: Review application and system access logs for anomalous patterns or unexpected requests directed toward the browser graphics or WebGPU subsystems.
Compensating Controls: While no direct virtual patch exists, ensuring that the browser is configured to restrict cross-origin requests and disabling unnecessary hardware acceleration features may reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability, combined with its potential for remote, unauthenticated exploitation, necessitates immediate action. Administrators must prioritize the deployment of the provided security updates across all endpoints to ensure the confidentiality of user data and system integrity.
More Mozilla CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written
- Published in the daily brief high section, early-warning entry
Sources
Originally found and disclosed by 5up3rh3i, per the CVE Program record.