CVE-2026-84130
massInformation Disclosure in Mozilla Firefox and Thunderbird WebGPU Component
CVE-2026-84130 is an information-disclosure vulnerability (CWE-200) in the Graphics: WebGPU component of Mozilla's Firefox browser and Thunderbird mail client. It is triggered remotely over the network when the affected application processes crafted content that exercises the WebGPU implementation, with low attack complexity and, per the CVSS vector, no privileges or user interaction required. A successful attacker gains access to sensitive information from the affected application (high confidentiality impact) with no impact on integrity or availability. All users running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR in versions prior to the fixed releases are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently estimates only about a 0.3% probability of exploitation within 30 days.
What to do: Upgrade to Firefox 155 or Firefox ESR 153.2, and Thunderbird 155 or Thunderbird 153.2, prioritizing endpoints that browse untrusted websites or render HTML mail. As an interim mitigation, consider disabling WebGPU (set dom.webgpu.enabled to false in about:config) until systems can be patched. No public PoC exists, so treat this as a routine but high-priority patch.
| mozilla Firefox | versions prior to 155 |
| mozilla Firefox ESR | versions prior to 153.2 |
| mozilla Thunderbird | versions prior to 155 |
| mozilla Thunderbird ESR | versions prior to 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.