An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Update Mozilla/Firefox to 97.0.2; Mozilla/Firefox ESR to 91.6.1; Mozilla/Firefox for Android to 97.3.0; Mozilla/Focus to 97.3.0; Mozilla/Thunderbird to 91.6.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCVE Program Container affects Mozilla/Firefox (generic), Mozilla/Firefox ESR (generic), Mozilla/Firefox for Android (generic), Mozilla/Focus (generic), Mozilla/Thunderbird (generic). Severity is high. This vulnerability is known to be exploited in the wild. An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Mozilla/Firefoxgeneric |
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Update Mozilla/Firefox to 97.0.2; Mozilla/Firefox ESR to 91.6.1; Mozilla/Firefox for Android to 97.3.0; Mozilla/Focus to 97.3.0; Mozilla/Thunderbird to 91.6.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCVE Program Container affects Mozilla/Firefox (generic), Mozilla/Firefox ESR (generic), Mozilla/Firefox for Android (generic), Mozilla/Focus (generic), Mozilla/Thunderbird (generic). Severity is high. This vulnerability is known to be exploited in the wild. An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Mozilla/Firefoxgeneric |
| >=unspecified <97.0.2 |
| 97.0.2 |
| Mozilla/Firefox ESRgeneric | >=unspecified <91.6.1 | 91.6.1 |
|---|
| Mozilla/Firefox for Androidgeneric | >=unspecified <97.3.0 | 97.3.0 |
|---|
| Mozilla/Focusgeneric | >=unspecified <97.3.0 | 97.3.0 |
|---|
| Mozilla/Thunderbirdgeneric | >=unspecified <91.6.2 | 91.6.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=unspecified <97.0.2 |
| 97.0.2 |
| Mozilla/Firefox ESRgeneric | >=unspecified <91.6.1 | 91.6.1 |
|---|
| Mozilla/Firefox for Androidgeneric | >=unspecified <97.3.0 | 97.3.0 |
|---|
| Mozilla/Focusgeneric | >=unspecified <97.3.0 | 97.3.0 |
|---|
| Mozilla/Thunderbirdgeneric | >=unspecified <91.6.2 | 91.6.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard