Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

High-Severity Vulnerabilities Patched in Chrome, Firefox

Google and Mozilla have released patches for multiple high-severity vulnerabilities affecting Chrome and Firefox.

Chrome and Firefox vulnerabilities

Google and Mozilla on Tuesday announced a fresh round of Chrome and Firefox patches, including fixes for high-severity vulnerabilities.

A new Chrome 139 iteration was released to resolve a high-severity out-of-bounds write issue in the V8 JavaScript engine, which is tracked as CVE-2025-9132.

The issue could be exploited remotely using crafted HTML pages, and was discovered by Google’s Big Sleep AI agent, which was launched by Google DeepMind and Project Zero in November 2024.

The internet giant did not share details on CVE-2025-9132, but it did say last month that Big Sleep can find vulnerabilities that attackers already know about and plan to use in attacks, enabling the industry to thwart their exploitation.

Fixes for the V8 flaw were included in Chrome versions 139.0.7258.138/.139 for Windows and macOS, and in version 139.0.7258.138 for Linux, which should reach all users shortly.

On Tuesday, Mozilla rolled out patches for nine security defects in Firefox, including five rated ‘high severity’. Fresh Thunderbird and Firefox ESR iterations were also released to resolve some of these bugs.

Advertisement. Scroll to continue reading.

The high-severity vulnerabilities include a memory corruption issue in the GMP process, leading to sandbox escape (CVE-2025-9179), a same-origin policy bypass in a graphics component (CVE-2025-9180), and multiple memory safety bugs that could potentially lead to remote code execution (CVE-2025-9187, CVE-2025-9184, and CVE-2025-9185).

The remaining flaws addressed with this Firefox release include a medium-severity uninitialized memory issue and low-severity spoofing and denial-of-service (DoS) bugs.

Fixes for these security holes were included in Firefox 142, Thunderbird 142, Thunderbird 140.2, Thunderbird 128.14, Firefox for iOS 142, Focus for iOS 142, Firefox ESR 140.2, Firefox ESR 128.14, and Firefox ESR 115.27.

Google and Mozilla make no mention of any of these vulnerabilities being exploited in attacks, but users are advised to update their browsers and email clients as soon as possible.

Related: Chrome Sandbox Escape Earns Researcher $250,000

Related: Google Project Zero Tackles Upstream Patch Gap With New Policy

Related: Cisco Patches Critical Vulnerability in Firewall Management Platform

Related: Meta Releases Llama AI Open Source Protection Tools

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.