CVE-2026-5733
HIGHIncorrect boundary conditions in the Graphics: WebGPU component
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-5733. PoCs published by Lechansky.
AI-analyzed exploit summary The repository lacks actual exploit code and instead directs users to an external download link (tinyurl.com). The README contains vague marketing language and no technical details about the vulnerability.
Description
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
Exploits (1)
nomisec
SUSPICIOUS
by Lechansky · poc
https://github.com/Lechansky/CVE-2026-5733
The repository lacks actual exploit code and instead directs users to an external download link (tinyurl.com). The README contains vague marketing language and no technical details about the vulnerability.
Classification
Suspicious 95%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target:
Firefox prior to 149.0.2
No auth needed
Prerequisites:
user interaction
MITRE ATT&CK
devstral-2 · analyzed Apr 08, 2026
Full analysis →
Scores
CVSS v3
8.8
EPSS
0.0028
EPSS Percentile
19.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-119
Status
published
Products (5)
mozilla/firefox
< 149.0.2
Mozilla/Firefox
149.0.2
Mozilla/Firefox
unspecified - 149.0.2
Mozilla/Thunderbird
149.0.2
Mozilla/Thunderbird
unspecified - 149.0.2
Published
Apr 07, 2026
Tracked Since
Apr 07, 2026