[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnqj0Kn3YLTMudRgdJBi9BuQ65omBHEN9uh_mcqK_XUk":3},{"article":4,"iocs":38},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"fa782382-f32d-43c5-8454-571e51077a7e","Chrome, Firefox Updates Patch Dozens of Vulnerabilities","chrome-firefox-updates-patch-dozens-of-vulnerabilities-3383e6","The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.","Google and Mozilla have released security updates for Chrome and Firefox, addressing a significant number of vulnerabilities. Firefox 154 includes patches for 58 CVEs, many of which are memory safety bugs that could lead to code execution. Google's Chrome 151 update resolves 15 vulnerabilities, including two critical buffer overflow bugs in WebGL and Dawn.","Chrome and Firefox release updates patching dozens of critical and high-severity vulnerabilities.","Google and Mozilla on Tuesday announced fresh Chrome and Firefox security updates that address multiple critical- and high-severity vulnerabilities. Firefox 154 was released to the stable channel with patches for 58 CVEs, including 20 high-severity flaws, roughly half of which are memory safety bugs that could be exploited for code execution. Resolved high-severity issues include six use-after-free defects, six privilege escalation vulnerabilities, two information disclosure bugs, one sandbox escape flaw, one site isolation issue, and one mitigation bypass weakness. Per Mozilla’s advisory, the update also resolves multiple internally discovered bugs leading to memory corruption and other security-related defects that could have been exploited. They were collectively assigned three CVEs. On Tuesday, Mozilla also announced the rollout of Thunderbird 154 with patches for 55 vulnerabilities. Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 140.14, and Thunderbird 153.1 were also released with fixes for dozens of these security defects. Google released a fresh Chrome 151 update that resolves 15 vulnerabilities, including two critical-severity buffer overflow bugs in WebGL and Dawn.Advertisement. Scroll to continue reading. The remaining 13 flaws are high-severity inappropriate implementation, link following, race condition, incorrect reference resolution, use-after-free, use of uninitialized resource, buffer overflow, incorrect calculation, information leak, and type confusion issues. Google says it found 11 of these security defects, while the other four were discovered and reported by external researchers. The company has yet to disclose the bug bounty amounts to be paid. The latest Chrome release is now rolling out to users as versions 151.0.7922.169\u002F.170 for Windows and macOS, and as version 151.0.7922.169 for Linux. Related: AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Related: 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw Related: GitLab Patches Critical Code Injection Vulnerability Related: Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Heights Finance Data Breach Impacts at Least 1.2 Million IndividualsGitLab Patches Critical Code Injection VulnerabilityDozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates680,000 Impacted by French Tax Authority Data Breach40,000 Impacted by SafePal Data BreachRecent macOS Screen Sharing Vulnerability Exploited in AttacksFortune 500 Companies Hit in Azure Data Theft CampaignTrivy, Not LiteLLM Behind the 2,500 Org Compromise Latest News 943 Patches Rolled Out With Oracle’s August 2026 Security UpdateCareCloud Data Breach Impact Grows to 3.7 Million IndividualsWebinar Today: Rethinking Cyber Defense for AI-Speed AttacksCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOWAI-Driven Vulnerability Surge Breaks the Traditional Patching ModelXpander Raises $7.5 Million for AI Management and GovernanceFortinet Acquires AI Security Company Virtue AI300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDali Rajic is joining OpenAI as Chief Revenue Officer.Erika Dean has been appointed Chief Information Security Officer at Tricentis.C1 has named Jeff St. Clair Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fchrome-firefox-updates-patch-dozens-of-vulnerabilities\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F01\u002FChrome-Firefox.jpeg","2026-08-19T08:19:09+00:00","2026-08-19T10:00:24.13264+00:00",8,[18,21,24,26,28],{"name":19,"type":20},"Chrome","product",{"name":22,"type":23},"Google","vendor",{"name":25,"type":20},"Firefox",{"name":27,"type":23},"Mozilla",{"name":29,"type":20},"Thunderbird","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":30,"icon":32,"name":33,"slug":34},null,"Vulnerabilities","vulnerabilities",[36],{"category":37},{"id":30,"icon":32,"name":33,"slug":34},[]]