Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Firefox 145 and Chrome 142 Patch High-Severity Flaws in Latest Releases

Google and Mozilla have released fresh Chrome and Firefox updates that address multiple high-severity security defects.

Chrome and Firefox vulnerabilities

Google and Mozilla on Tuesday released fresh updates for Chrome and Firefox to resolve multiple high-severity vulnerabilities.

Google announced a Chrome 142 update that resolves a high-severity inappropriate implementation issue in the V8 JavaScript engine. The bug is tracked as CVE-2025-13042.

The internet giant has not detailed the flaw, but such V8 defects can typically be exploited remotely to cause denial-of-service (DoS) conditions or for code execution, Hong Kong CERT/CC notes. Google has yet to determine the bug bounty reward for the defect.

The latest Chrome iteration is now rolling out as version 142.0.7444.162 for Linux, version 142.0.7444.162 for macOS, and versions 142.0.7444.162/.163 for Windows.

Mozilla on Tuesday released Firefox 145 to the stable channel with fixes for 16 vulnerabilities, including nine high-severity weaknesses, and with improved anti-fingerprinting protections.

Six of these security defects impact the browser’s graphics, and five of them are described as incorrect boundary conditions issues affecting the WebGPU component. The sixth is a race condition.

Advertisement. Scroll to continue reading.

Firefox 145 also resolves an incorrect boundary conditions flaw in the WebAssembly component, and a JIT miscompilation bug in the JavaScript Engine.

The ninth high-severity bug, tracked as CVE-2025-13027, collectively identifies memory safety flaws impacting Firefox 144 and Thunderbird 144.

On Tuesday, Mozilla also released Firefox ESR 140.5 with fixes for nine security defects, and Firefox ESR 115.30 with patches for four weaknesses.

Google and Mozilla make no mention of any of these vulnerabilities being exploited in the wild.

Related: Chrome 142 Update Patches High-Severity Flaws

Related: New Firefox Extensions Required to Disclose Data Collection Practices

Related: High-Severity Vulnerabilities Patched by Ivanti and Zoom

Related: Google Paid Out $458,000 at Live Hacking Event

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Malwarebytes has named Chung Ip as Chief Financial Officer.

Semperis has appointed John Podboy as Chief Information Security Officer.

Randy Menon has become Chief Product and Marketing Officer at One Identity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.