CVE-2026-5733

HIGH

Incorrect boundary conditions in the Graphics: WebGPU component

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-5733. PoCs published by Lechansky.

AI-analyzed exploit summary The repository lacks actual exploit code and instead directs users to an external download link (tinyurl.com). The README contains vague marketing language and no technical details about the vulnerability.

Description

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.

Exploits (1)

nomisec SUSPICIOUS
by Lechansky · poc
https://github.com/Lechansky/CVE-2026-5733

The repository lacks actual exploit code and instead directs users to an external download link (tinyurl.com). The README contains vague marketing language and no technical details about the vulnerability.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Firefox prior to 149.0.2
No auth needed
Prerequisites: user interaction
devstral-2 · analyzed Apr 08, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0028
EPSS Percentile 19.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (5)
mozilla/firefox < 149.0.2
Mozilla/Firefox 149.0.2
Mozilla/Firefox unspecified - 149.0.2
Mozilla/Thunderbird 149.0.2
Mozilla/Thunderbird unspecified - 149.0.2
Published Apr 07, 2026
Tracked Since Apr 07, 2026