Chrome, Firefox updates fix 115 security flaws overall

Google and Mozilla have shipped new security updates for Chrome and Firefox that collectively fix 115 security vulnerabilities, including several rated critical in the browser engines and supporting components.[1][5] The latest Chrome 153 stable release patches 42 security defects, while Firefox 156 resolves 73 bugs, continuing a rapid cadence of browser security hardening across desktop platforms.[1][5]

On the Chrome side, the 153 update includes three critical-severity flaws and 28 high-severity issues affecting components such as WebGL, Internals and Workers.[1] Among the most serious are CVE-2026-91726, an out-of-bounds read in WebGL that could enable information disclosure or crashes, and CVE-2026-91721 and CVE-2026-91749, use-after-free bugs in Internals and Workers that open the door to arbitrary code execution if successfully exploited.[1] Google is rolling out the fixed builds as Chrome 153.0.8010.47/.48 for Windows and macOS and 153.0.8010.47 for Linux, with automatic updates enabled for most users.[1]

Mozilla’s Firefox 156 release closes 73 vulnerabilities across the browser, its JavaScript engine and related subsystems, with 29 of those issues classified as high-severity.[1] Many of the flaws fall into familiar categories like memory corruption, sandbox escape and information disclosure, areas that have long been prime targets for exploit developers.[1] Mozilla has documented the fixes in its security advisories portal, which aggregates technical details and impact assessments for recent Firefox and Firefox ESR patches to help enterprise defenders track exposure across versions.[4]

The new Chrome and Firefox fixes arrive amid an active threat landscape that has already seen multiple browser zero-days exploited in 2026.[6][7][10][15] Earlier this month, Google separately patched CVE-2026-85046, a type confusion vulnerability in the V8 JavaScript engine that was being used in real-world attacks and carries a CVSS score of 8.8.[7][10] That bug was addressed in Chrome 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux, marking at least the sixth Chrome zero-day disclosed this year and underscoring how quickly offensive teams move to weaponize memory-safety issues.[6][7][10][15]

For organizations, the combined tally of 115 newly patched vulnerabilities in Chrome 153 and Firefox 156 is a reminder that modern browsers remain high-value targets and should be treated as core infrastructure from a patch-management perspective.[1][2][3] Security teams are urged to verify that automatic updating is enabled, prioritize rolling out the latest builds to high-risk users such as developers and administrators, and rapidly retire older browser versions that no longer receive fixes.[1][4] Where strict change-control processes exist, defenders should at minimum push the new releases into testing immediately, monitor vendor advisories for any post-release revisions, and update endpoint detection rules to watch for exploit chains attempting to leverage browser memory-corruption bugs.

References

  1. Chrome, Firefox Updates Patch 115 Vulnerabilities
  2. Chrome and Firefox Updates Patch Dozens of Vulnerabilities
  3. Chrome, Firefox Updates Patch Dozens of Vulnerabilities
  4. Mozilla Foundation Security Advisories
  5. SecurityWeek: Cybersecurity News, Insights and Analysis
  6. September 2026 Patch Tuesday
  7. Chrome Patches Sixth Zero-Day of 2026 as V8 Compiler …
  8. Google patches multiple Chrome bugs including a V8 flaw being used in attacks
  9. Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply