Download Privacy Needle App

Type to search

Cybersecurity

Google and Mozilla Patch 115 Vulnerabilities in Chrome and Firefox

Share

Google and Mozilla have released critical security updates for their respective web browsers, addressing a combined total of 115 vulnerabilities. The updates target significant security defects in Google Chrome and Mozilla Firefox, including several critical-severity flaws.

Google Chrome Patches Critical Vulnerabilities

The latest Google Chrome 153 release resolves 42 security defects. This update includes three critical-severity vulnerabilities:

  • CVE-2026-91726: An out-of-bounds read issue in WebGL.
  • CVE-2026-91721: A use-after-free vulnerability in Internals.
  • CVE-2026-91749: A use-after-free vulnerability in Workers.

In addition to the critical flaws, the update addresses 28 high-severity bugs involving type confusion, integer overflow, race conditions, and incorrect authorisation. Chrome versions 153.0.8010.47 and 153.0.8010.48 are being rolled out for Windows and macOS, while Linux users will receive version 153.0.8010.47.

Mozilla Firefox and Thunderbird Updates

Mozilla has announced the release of Firefox 156, which includes fixes for 73 vulnerabilities. Of these, 29 are classified as high-severity. The addressed flaws primarily involve use-after-free and privilege escalation issues, alongside weaknesses related to sandbox escape, site isolation, and mitigation bypasses.

Mozilla noted that the higher number of CVEs in this release is due to the decision to track each individual memory safety issue separately, rather than grouping them under a single identifier as was done in previous advisories.

The security fixes also extend to other Mozilla products, including Thunderbird versions 156 and 140.16, and Firefox Extended Support Release (ESR) versions 153.3, 140.16, and 115.41.

User Guidance

While neither Google nor Mozilla has reported that any of these security defects are being exploited in the wild, users are advised to update their browsers to the latest versions immediately to mitigate the risk of exploitation.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.