Google and Mozilla on Tuesday announced patches for dozens of vulnerabilities in Chrome and Firefox, including critical and high severity vulnerabilities.
A new Chrome 152 update has been released with fixes for 26 bugs, two of which are critical use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352).
The update also addresses nine serious security flaws, including use-after-free vulnerabilities, false authorization, information leaks, improper input validation, uninitialized resources, and buffer overflow vulnerabilities.
The remaining 15 vulnerabilities are medium and low severity issues. According to Google advisoryOnly three of the bugs were reported by external researchers, but no bug bounty reward was announced.
The latest Chrome iteration is now rolling out as version 152.0.7977.75/.76 for Windows and macOS, and version 152.0.7977.75 for Linux.
Mozilla was introduced Firefox 155 with patches for 29 security flaws, including 13 high-level use-after-free, sandbox escape, and memory corruption issues.
The bugs have been fixed in Firefox’s GC, Navigation, Audio/Video, Security, WebGPU, Core, and HTML and Grid components, as well as Firefox for Android. Three of the released CVEs cover multiple bugs that cause memory corruption and could potentially have been exploited “with enough effort.”
On Tuesday also Mozilla announced the release of Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15 and Thunderbird 153.2 with fixes for these vulnerabilities.
Google and Mozilla make no mention of these vulnerabilities being exploited in the wild.
Related: SonicWall warns of two SMA1000 zero-days being exploited in attacks
Related: Hackers begin exploiting critical Langflow vulnerability
Related: A critical vulnerability in JFrog Artifactory has reportedly been exploited in the wild
Related: WatchGuard fixes critical vulnerabilities
