Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Chrome and Firefox release updates patching over 100 vulnerabilities, including critical flaws.
Summary
Google and Mozilla have released significant updates for Chrome and Firefox, addressing a combined total of over 100 vulnerabilities. Chrome's update includes fixes for 32 security defects, with one critical buffer overflow in ANGLE. Firefox's update addresses approximately 76 vulnerabilities, many of which are high-severity use-after-free and sandbox escape bugs. While no active exploitation has been reported, users are strongly advised to update their browsers promptly.
Full text
Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities. The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher. Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine. The browser update also fixes high-severity improper privilege management, UI misconfiguration, out-of-bounds read/write, cross-site scripting (XSS), and buffer overflow issues. External researchers reported 15 of the patched security holes, but Google has not disclosed the bounty rewards paid for 14 of them. According to its advisory, the company handed out $1,000 for a low-severity missing authorization bug in Payments. The latest Chrome iteration is now rolling out to users as versions 154.0.8037.92/.93 for Windows and macOS, and as version 154.0.8037.92 for Linux.Advertisement. Scroll to continue reading. Mozilla released Firefox 157 with patches for approximately 76 vulnerabilities, including 38 high-severity security defects, mostly use-after-free and sandbox escape bugs. The fresh Firefox update also resolves high-severity incorrect boundary conditions, uninitialized memory, privilege escalation, information disclosure, invalid pointer, and JIT miscompilation issues. Many of the vulnerabilities resolved in Firefox 157 were also fixed in Firefox ESR 153.4, 140.17, and 115.42. Google and Mozilla make no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible. Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Reco Raises $55 Million for Agentic SecurityHackers Use ChatGPT Custom GPTs in ClickFix AttacksDutch Police Arrest Convicted Hacker in ShinyHunters InvestigationDaemon Tools Hackers’ NeedyMantis Malware Dissected by MicrosoftPrison Sentence for Former US Soldier Who Hacked AT&T and VerizonDC Health Agency Exposes 400,000 Beneficiary RecordsGoogle Warns of ShinyHunters’ Fresh Oracle PeopleSoft CampaignKiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability Latest News WatchGuard Patches Critical Fireware OS Code Injection VulnerabilityGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLTrump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI DevelopmentOpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the Move David Cass has joined Grayscale Investments as Chief Risk Officer. He joins the crypto investment funds firm from Keyrock, where he served as Chief Information Security Officer. Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.Alex Stamos has become Chief Information Security Officer at Cognition.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-102331