Back Securityweek Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities.
The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher.
Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine.
The browser update also fixes high-severity improper privilege management, UI misconfiguration, out-of-bounds read/write, cross-site scripting (XSS), and buffer overflow issues.
External researchers reported 15 of the patched security holes, but Google has not disclosed the bounty rewards paid for 14 of them. According to its advisory, the company handed out $1,000 for a low-severity missing authorization bug in Payments.
The latest Chrome iteration is now rolling out to users as versions 154.0.8037.92/.93 for Windows and macOS, and as version 154.0.8037.92 for Linux.
Mozilla released Firefox 157 with patches for approximately 76 vulnerabilities, including 38 high-severity security defects, mostly use-after-free and sandbox escape bugs.
The fresh Firefox update also resolves high-severity incorrect boundary conditions, uninitialized memory, privilege escalation, information disclosure, invalid pointer, and JIT miscompilation issues.
Many of the vulnerabilities resolved in Firefox 157 were also fixed in Firefox ESR 153.4, 140.17, and 115.42.
Google and Mozilla make no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible.
Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
Reco Raises $55 Million for Agentic Security
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
DC Health Agency Exposes 400,000 Beneficiary Records
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
ShinyHunters Defiant After FBI Calls on Members to Come Forward
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
DARPA Selects Xint to Use AI in Securing Military Messaging Apps
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
