CRITICAL🇵🇱 Wersja polska

CVE-2025-13021

CVSS 9.8v3.1pub. 2025-11-11upd. 2026-04-13

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

🤖 AI Analysis
How it works

The WebGPU component is responsible for handling graphics and GPU hardware acceleration in the browser. Due to improperly defined boundary conditions (CWE-703 — improper handling of exceptions or error conditions), specially crafted graphic content may trigger unexpected behavior during data processing by the WebGPU engine. An attacker can deliver malicious content over the network without requiring authentication or interaction from the victim, making this vulnerability particularly dangerous.

Impact

Successful exploitation of the vulnerability may allow an attacker to execute code remotely (RCE) in the context of the browser process, and consequently gain full control over the attacked system — compromising its confidentiality, integrity, and availability.

Mitigation & patch

Mozilla Firefox browser should be updated immediately to version 145 or later, and Mozilla Thunderbird mail client should be updated to version 145 or later. Patches are available through official Mozilla distribution channels.

Who is affected

Mozilla Firefox in versions prior to Firefox 145 and Mozilla Thunderbird in versions prior to Thunderbird 145.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mozilla Firefox

    APP
    Mozilla
    < 145.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product

Use-after-free w Animation timelines Firefox/Thunderbird — RCE

CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w WebGPU IPC framework Mozilla — sandbox escape

CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓same product

Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open

CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓same product

RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended

CVE-2026-84119CRITICAL9.6same product

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...