Back to Feed
VulnerabilitiesSep 2, 2026

Chrome and Firefox Updates Patch Dozens of Vulnerabilities

Chrome and Firefox release updates to fix dozens of critical and high-severity vulnerabilities.

Summary

Google and Mozilla have released patches for numerous vulnerabilities affecting their respective browsers, Chrome and Firefox. The Chrome 152 update addresses 26 bugs, including two critical use-after-free issues. Firefox 155 resolves 29 security defects, with a focus on memory corruption and sandbox escape flaws. Both companies have not reported any exploitation of these vulnerabilities in the wild.

Full text

Google and Mozilla on Tuesday announced patches for dozens of vulnerabilities across Chrome and Firefox, including critical- and high-severity flaws. A fresh Chrome 152 update has been rolled out with fixes for 26 bugs, two of which are critical-severity use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352). The update also addresses nine high-severity security defects, including use-after-free, incorrect authorization, information leak, improper input validation, uninitialized resource, and buffer overflow weaknesses. The remaining 15 vulnerabilities are medium- and low-severity issues. Per Google’s advisory, only three of the flaws were reported by external researchers, but no bug bounty reward has been disclosed. The latest Chrome iteration is now rolling out as versions 152.0.7977.75/.76 for Windows and macOS, and as version 152.0.7977.75 for Linux. Mozilla rolled out Firefox 155 with patches for 29 security defects, including 13 high-severity use-after-free, sandbox escape, and memory corruption issues.Advertisement. Scroll to continue reading. The flaws were addressed in Firefox’s GC, Navigation, Audio/Video, Security, WebGPU, Core & HTML, and Grid components, and in Firefox for Android. Three of the issued CVEs cover multiple bugs leading to memory corruption that could have been potentially exploited “with enough effort”. On Tuesday, Mozilla also announced the release of Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2 with fixes for these vulnerabilities. Google and Mozilla make no mention of any of these vulnerabilities being exploited in the wild. Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Related: Hackers Start Exploiting Critical Langflow Vulnerability Related: Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild Related: WatchGuard Patches Critical Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Ransomware Gang Claims Nutex Health Data Breach9.5 Million Impacted by Aesto Health Data BreachWatchGuard Patches Critical VulnerabilitiesServiceNow Patches 3 Critical Code Injection VulnerabilitiesMcKesson Confirms Data Breach as Attacker Deadline LoomsCritical Ruby on Rails Vulnerability in Attackers’ CrosshairsExtortion Group Claims Manchester Airports Group Data BreachBerlin Won’t Pay Extortion Group Claiming Data Theft Latest News 23-Year-Old Sality P2P Botnet DisruptedSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksPalo Alto Networks Acquires AI Agent Platform ConsoleSevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseCoast Guard Establishes Office of Maritime Cybersecurity PolicyExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsHackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM Jackpotting Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSectigo has named Ian Hassard as Chief Product Officer.Australian Securities Exchange has appointed Hanlie Botha as Deputy Chief Information Security Officer.Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-84353
  • cve — CVE-2026-84352

Entities

Chrome (product)Google (vendor)Firefox (product)Mozilla (vendor)Firefox ESR (product)Thunderbird (product)