Chrome, Firefox Updates Patch 115 Vulnerabilities
Chrome and Firefox release updates patching 115 vulnerabilities, including critical flaws.
Summary
Google and Mozilla have released significant security updates for their respective browsers, Chrome and Firefox. Chrome 153 addresses 42 vulnerabilities, three of which are critical, while Firefox 156 fixes 73 bugs, including 29 high-severity issues. The updates cover a range of weaknesses such as out-of-bounds reads, use-after-free, and privilege escalation. Users are strongly advised to update their browsers immediately.
Full text
Google and Mozilla have released fresh security updates for Chrome and Firefox users, resolving a total of 115 vulnerabilities. The new Chrome 153 release patches 42 security defects, including three critical-severity and 28 high-severity bugs. The critical flaws include CVE-2026-91726, an out-of-bounds read in WebGL, and CVE-2026-91721 and CVE-2026-91749, use-after-free issues in Internals and Workers, respectively. Google also resolved multiple high-severity use-after-free, race condition, type confusion, integer overflow, incorrect authorization, and uninitialized resource weaknesses. Of the resolved vulnerabilities, 16 were reported by external researchers, but Google has yet to disclose 14 of the bug bounty amounts it paid out. Only two rewards totaling $2,500 were disclosed. The latest Chrome iteration is now rolling out as versions 153.0.8010.47/.48 for Windows and macOS, and as version 153.0.8010.47 for Linux.Advertisement. Scroll to continue reading. Mozilla announced the release of Firefox 156 with fixes for 73 vulnerabilities, including 29 high-severity bugs. Most of the addressed high-severity flaws are use-after-free and privilege escalation issues, but the browser update also resolves sandbox escape, site isolation, incorrect boundary condition, and mitigation bypass weaknesses. Unlike previous Mozilla advisories that collectively tracked memory safety issues identified internally under a single CVE, the fresh release mentions each individual bug, which explains the larger number of CVEs. Dozens of these security issues were also addressed in the newly released Thunderbird 156 and 140.16, and in Firefox ESR 153.3, 140.16, and 115.41. Google and Mozilla make no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible. Related: Enterprises Warned of Attacks Exploiting WSO2 Vulnerability Related: Oracle Patches 800+ Vulnerabilities in September 2026 Security Update Related: “We Think the Security Control Is Working” Is No Longer Good Enough Related: Chrome 153 Patches Seventh Zero-Day of 2026 Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Exein Secures $270M at $1.7B Valuation for Physical AI SecurityThai Broadband Provider Hacked via Fortinet Vulnerability240,000 Hit by Data Breach at Japan’s Digital AgencyApple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackPersonal, Financial Info Exposed in Revolut Data BreachChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionThree JFrog Artifactory Flaws Exploited for Backdoor Deployment Latest News Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to TakeoverHackuity Raises $19 Million for AI-Powered Vulnerability Management280,000 Impacted by Premier Medical Group Data BreachAcronis Patches Exploited Vulnerability in cPanel Backup PluginEnterprises Warned of Attacks Exploiting WSO2 VulnerabilityOracle Patches 800+ Vulnerabilities in September 2026 Security UpdateMicrosoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?“We Think the Security Control Is Working” Is No Longer Good Enough Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveFrank Krieger has been named Chief Information Security Officer at Swap.Geoff Belknap has joined HubSpot as Chief Trust Officer.Zero Networks has named Yossi Dagan as Chief Financial Officer.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-91726
- cve — CVE-2026-91721
- cve — CVE-2026-91749