Back Securityweek Chrome and Firefox Updates Patch Dozens of Vulnerabilities
Google and Mozilla on Tuesday announced patches for dozens of vulnerabilities across Chrome and Firefox, including critical- and high-severity flaws.
A fresh Chrome 152 update has been rolled out with fixes for 26 bugs, two of which are critical-severity use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352).
The update also addresses nine high-severity security defects, including use-after-free, incorrect authorization, information leak, improper input validation, uninitialized resource, and buffer overflow weaknesses.
The remaining 15 vulnerabilities are medium- and low-severity issues. Per Google’s advisory , only three of the flaws were reported by external researchers, but no bug bounty reward has been disclosed.
The latest Chrome iteration is now rolling out as versions 152.0.7977.75/.76 for Windows and macOS, and as version 152.0.7977.75 for Linux.
Mozilla rolled out Firefox 155 with patches for 29 security defects, including 13 high-severity use-after-free, sandbox escape, and memory corruption issues.
The flaws were addressed in Firefox’s GC, , Audio/Video, Security, WebGPU, Core & HTML, and Grid components, and in Firefox for Android. Three of the issued CVEs cover multiple bugs leading to memory corruption that could have been potentially exploited “with enough effort”.
On Tuesday, Mozilla also announced the release of Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2 with fixes for these vulnerabilities.
Google and Mozilla make no mention of any of these vulnerabilities being exploited in the wild.
Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Related: Hackers Start Exploiting Critical Langflow Vulnerability
Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
Related: WatchGuard Patches Critical Vulnerabilities
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
Exploit Published for Fresh Cleo Harmony Vulnerability
The security defect allows remote attackers to bypass authentication through argument bearer manipulation.
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.
Artificial Intelligence
Hackers Start Exploiting Critical Langflow Vulnerability
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.
Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.
WatchGuard Patches Critical Vulnerabilities
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.
PaperCut Exploitation Escalates to Active Intrusions
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.
Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
