Vulnerabilities

Chrome, Firefox Updates Patch Dozens of Vulnerabilities

The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.

Chrome and Firefox vulnerabilities

Google and Mozilla on Tuesday announced fresh Chrome and Firefox security updates that address multiple critical- and high-severity vulnerabilities.

Firefox 154 was released to the stable channel with patches for 58 CVEs, including 20 high-severity flaws, roughly half of which are memory safety bugs that could be exploited for code execution.

Resolved high-severity issues include six use-after-free defects, six privilege escalation vulnerabilities, two information disclosure bugs, one sandbox escape flaw, one site isolation issue, and one mitigation bypass weakness.

Per Mozilla’s advisory, the update also resolves multiple internally discovered bugs leading to memory corruption and other security-related defects that could have been exploited. They were collectively assigned three CVEs.

On Tuesday, Mozilla also announced the rollout of Thunderbird 154 with patches for 55 vulnerabilities. Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 140.14, and Thunderbird 153.1 were also released with fixes for dozens of these security defects.

Google released a fresh Chrome 151 update that resolves 15 vulnerabilities, including two critical-severity buffer overflow bugs in WebGL and Dawn.

Advertisement. Scroll to continue reading.

The remaining 13 flaws are high-severity inappropriate implementation, link following, race condition, incorrect reference resolution, use-after-free, use of uninitialized resource, buffer overflow, incorrect calculation, information leak, and type confusion issues.

Google says it found 11 of these security defects, while the other four were discovered and reported by external researchers. The company has yet to disclose the bug bounty amounts to be paid.

The latest Chrome release is now rolling out to users as versions 151.0.7922.169/.170 for Windows and macOS, and as version 151.0.7922.169 for Linux.

Related: AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

Related: 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Related: GitLab Patches Critical Code Injection Vulnerability

Related: Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates

Related Content

Vulnerabilities

The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs.

Artificial Intelligence

Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores.

Vulnerabilities

Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.

Vulnerabilities

The security defect allows unauthenticated attackers to modify or delete user data and public projects.

Mobile & Wireless

The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data.

Vulnerabilities

Threat actors gained root access to the vulnerable systems and deployed a Monero miner.

Vulnerabilities

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.

Vulnerabilities

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version