ZeroHour

CVE-2026-84130

mass

Information Disclosure in Mozilla Firefox and Thunderbird WebGPU Component

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-84130 is an information-disclosure vulnerability (CWE-200) in the Graphics: WebGPU component of Mozilla's Firefox browser and Thunderbird mail client. It is triggered remotely over the network when the affected application processes crafted content that exercises the WebGPU implementation, with low attack complexity and, per the CVSS vector, no privileges or user interaction required. A successful attacker gains access to sensitive information from the affected application (high confidentiality impact) with no impact on integrity or availability. All users running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR in versions prior to the fixed releases are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Upgrade to Firefox 155 or Firefox ESR 153.2, and Thunderbird 155 or Thunderbird 153.2, prioritizing endpoints that browse untrusted websites or render HTML mail. As an interim mitigation, consider disabling WebGPU (set dom.webgpu.enabled to false in about:config) until systems can be patched. No public PoC exists, so treat this as a routine but high-priority patch.

Affected
mozilla Firefoxversions prior to 155
mozilla Firefox ESRversions prior to 153.2
mozilla Thunderbirdversions prior to 155
mozilla Thunderbird ESRversions prior to 153.2
Estimated exposure
masshundreds of millions of users (roughly 200-300 million Firefox users plus tens of millions of Thunderbird users) — Firefox historically counts roughly 200-300 million monthly active users per public usage statistics and Thunderbird has tens of millions of desktop users, and all installs on pre-fix builds (before 155 / 153.2) are exposed until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.