Google and Mozilla Patch 115 Vulnerabilities in Chrome and Firefox
Share
Google and Mozilla have released critical security updates for their respective web browsers, addressing a combined total of 115 vulnerabilities. The updates target significant security defects in Google Chrome and Mozilla Firefox, including several critical-severity flaws.
Google Chrome Patches Critical Vulnerabilities
The latest Google Chrome 153 release resolves 42 security defects. This update includes three critical-severity vulnerabilities:
- CVE-2026-91726: An out-of-bounds read issue in WebGL.
- CVE-2026-91721: A use-after-free vulnerability in Internals.
- CVE-2026-91749: A use-after-free vulnerability in Workers.
In addition to the critical flaws, the update addresses 28 high-severity bugs involving type confusion, integer overflow, race conditions, and incorrect authorisation. Chrome versions 153.0.8010.47 and 153.0.8010.48 are being rolled out for Windows and macOS, while Linux users will receive version 153.0.8010.47.
Mozilla Firefox and Thunderbird Updates
Mozilla has announced the release of Firefox 156, which includes fixes for 73 vulnerabilities. Of these, 29 are classified as high-severity. The addressed flaws primarily involve use-after-free and privilege escalation issues, alongside weaknesses related to sandbox escape, site isolation, and mitigation bypasses.
Mozilla noted that the higher number of CVEs in this release is due to the decision to track each individual memory safety issue separately, rather than grouping them under a single identifier as was done in previous advisories.
The security fixes also extend to other Mozilla products, including Thunderbird versions 156 and 140.16, and Firefox Extended Support Release (ESR) versions 153.3, 140.16, and 115.41.
User Guidance
While neither Google nor Mozilla has reported that any of these security defects are being exploited in the wild, users are advised to update their browsers to the latest versions immediately to mitigate the risk of exploitation.




Leave a Reply