Skip to content
Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Securityweek • September 30, 2026

Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities.

The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher.

Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine.

The browser update also fixes high-severity improper privilege management, UI misconfiguration, out-of-bounds read/write, cross-site scripting (XSS), and buffer overflow issues.

External researchers reported 15 of the patched security holes, but Google has not disclosed the bounty rewards paid for 14 of them. According to its advisory, the company handed out $1,000 for a low-severity missing authorization bug in Payments.

The latest Chrome iteration is now rolling out to users as versions 154.0.8037.92/.93 for Windows and macOS, and as version 154.0.8037.92 for Linux.

Mozilla released Firefox 157 with patches for approximately 76 vulnerabilities, including 38 high-severity security defects, mostly use-after-free and sandbox escape bugs.

The fresh Firefox update also resolves high-severity incorrect boundary conditions, uninitialized memory, privilege escalation, information disclosure, invalid pointer, and JIT miscompilation issues.

Many of the vulnerabilities resolved in Firefox 157 were also fixed in Firefox ESR 153.4, 140.17, and 115.42.

Google and Mozilla make no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible.

Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’

Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Artificial Intelligence

Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.