news.mlab.sh
Back to the feed
vulnerability

Chrome, Firefox Updates Patch 115 Vulnerabilities

CriticalCVSS 9.6
Summary

Google and Mozilla have released security updates for Chrome and Firefox, addressing 115 vulnerabilities across both browsers. The updates include critical and high-severity bugs, with a focus on memory safety issues and potential exploitation risks. Users are strongly encouraged to update immediately to mitigate potential security threats.

Google and Mozilla have released security updates for Chrome and Firefox, addressing a significant number of vulnerabilities. The updates aim to bolster the security of these widely used browsers and protect users from potential attacks.

Google’s Chrome 153 release patches 42 security defects, including three critical-severity and 28 high-severity bugs. These flaws encompass a range of issues, such as out-of-bounds reads in WebGL (CVE-2026-91726), use-after-free problems in Internals and Workers (CVE-2026-91721 and CVE-2026-91749), and other vulnerabilities related to memory management and authorization. Mozilla, on the other hand, released Firefox 156 with fixes for 73 vulnerabilities, including 29 high-severity bugs. Many of these flaws are use-after-free and privilege escalation issues, alongside sandbox escapes and site isolation weaknesses.

Google has not yet disclosed the monetary rewards paid to external researchers who identified these vulnerabilities, with only two rewards totaling $2,500 being revealed. Mozilla’s update also includes fixes for Thunderbird 156 and 140.16, and Firefox ESR 153.3, 140.16, and 115.41.

Neither Google nor Mozilla have indicated that these vulnerabilities are currently being exploited in the wild, but they strongly advise users to update their browsers to the latest versions to minimize risk. The release of these updates underscores the ongoing effort to maintain the security and stability of these essential software products.

Read the full article at SecurityWeek