Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +1 more
- < 144.0.2
A use-after-free vulnerability has been identified in Mozilla Firefox versions prior to 144.0.2. This issue arises from WebGPU-related inter-process communication (IPC) calls, starting with Firefox 142. A compromised child process could exploit this vulnerability to trigger the use-after-free condition in the GPU or browser process, potentially escaping the child process sandbox.
Exploitation of this vulnerability could lead to a sandbox escape from a compromised child process.
Users can upgrade to Firefox 144.0.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.