Critical Chrome and Firefox Flaws Patched Amid Exploitation Risks

Critical Chrome and Firefox Flaws Patched Amid Exploitation Risks

First seen 2 Sep 2026, 14:46 UTC SecurityweekMalwarebyteschromereleases.googleblog.comwww.cve.org 57.8

Article Content

Browse articles
ThreatCluster

On September 2, 2026, Google and Mozilla released updates for Chrome and Firefox, addressing a total of 55 vulnerabilities, including two critical use-after-free flaws in Chrome (CVE-2026-84353 and CVE-2026-84352). These vulnerabilities could allow remote attackers to execute arbitrary code via crafted HTML pages, particularly through social engineering tactics. The Chrome update (version 152.0.7977.75/.76) fixes 26 bugs, while Firefox's update (version 155) addresses 29 security defects, including 13 high-severity issues. Despite the critical nature of these vulnerabilities, both companies reported no known exploitation in the wild at the time of the updates. Users are advised to update their browsers promptly to mitigate potential risks. The updates are rolling out for Windows, macOS, and Linux systems.

Key Points: • Two critical use-after-free vulnerabilities in Chrome could allow remote code execution. • Google and Mozilla released updates for 55 vulnerabilities across Chrome and Firefox. • No known exploitation of these vulnerabilities has been reported yet.

Timeline

2026-01-23
CVE-2026-0768 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
Multiple CVEs published
CVE-2026-82078, CVE-2026-81578, and CVE-2026-82329 were published, with some added to CISA KEV for active exploitation.
Securityweek
2026-08-28
CVE-2026-82078 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-81578 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-82329 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
Critical Chrome flaws disclosed
CVE-2026-84353 and CVE-2026-84352 were published, detailing critical use-after-free vulnerabilities in Chrome.
Malwarebytes
2026-09-01
CVE-2026-83548 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83549 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84353 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-84352 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE