CVE-2026-16384
Mozilla Firefox ≤ 153.0.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NSummary
CVE-2026-16384 is a high-severity Use of Uninitialized Resource (CWE-908) vulnerability in Mozilla Firefox. Its CVSS base score is 7.5 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Drive-by Compromise (T1189); ranked at the 24th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SC-39 (Process Isolation) and SI-16 (Memory Protection) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-46221
Vulnerability Data
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Browser info disclosure vuln via uninitialized memory enables drive-by compromise for data leaks from local system/browser process.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces memory protection mechanisms that prevent reads of uninitialized memory, blocking the exact CWE-908 information disclosure in the WebGPU component.
Process isolation confines the WebGPU graphics process so that uninitialized memory contents cannot leak outside its sandboxed address space.
Least functionality allows disabling or restricting the WebGPU feature entirely, eliminating the attack surface for this uninitialized-memory disclosure.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC activities such as static analysis and code review directly prevent use of uninitialized resources while also addressing many other weaknesses.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development and acceptance can detect uninitialized resource usage through dynamic analysis and fuzzing.
Secure development life cycle mandates initialization checks and static analysis that can catch uninitialized resource use.
Application security requirements can specify mandatory initialization of variables and resources before use.
Secure system architecture and engineering principles include defensive coding practices that prevent use of uninitialized memory or objects.
Secure coding standards directly require explicit initialization of all variables and resources, substantially mitigating CWE-908.