Mozilla disclosed two high-severity Firefox vulnerabilities affecting graphics-related code and released fixes in Firefox 149.0.2. CVE-2026-5733 impacts the Graphics: WebGPU component and is described as incorrect boundary conditions under CWE-119, while CVE-2026-5732 affects the Graphics: Text component and involves an integer overflow caused by incorrect boundary conditions under CWE-190.
Both flaws carry a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating that remote exploitation with user interaction could have severe effects on confidentiality, integrity, and availability. Mozilla said CVE-2026-5732 affects Firefox versions earlier than 149.0.2 and Firefox ESR versions earlier than 140.9.1, while CVE-2026-5733 affects Firefox versions earlier than 149.0.2; the company linked the disclosures to Bugzilla entries and security advisories documenting the issues and available patches.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Mozilla disclosed CVE-2026-5732, an integer overflow caused by incorrect boundary conditions in Graphics: Text, and CVE-2026-5733, incorrect boundary conditions in Graphics: WebGPU. On the same date, the CVE records were updated with severity details, CWE classifications, and references to Bugzilla and Mozilla security advisories.
Mozilla made available fixes for two high-severity Firefox vulnerabilities: CVE-2026-5733 in the Graphics: WebGPU component and CVE-2026-5732 in the Graphics: Text component. The advisories indicate the issues affect Firefox versions earlier than 149.0.2, and for CVE-2026-5732 also Firefox ESR versions earlier than 140.9.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.