Chrome and Firefox updates fix over 100 vulnerabilities

Chrome and Firefox updates fix over 100 vulnerabilities

Google and Mozilla released new versions of Chrome and Firefox on Tuesday, and together the two updates fix more than 100 security vulnerabilities.

Neither company says any of these flaws have been exploited in the wild. Both still recommend that users update their browsers as soon as possible.

Chrome 154: one critical bug and a long list of high-severity fixes

The new Chrome release fixes 32 security defects. The most serious is a critical-severity buffer overflow in ANGLE, the graphics abstraction layer Chrome uses to translate web graphics calls for the underlying system. It is tracked as CVE-2026-102331 and was reported by an external researcher.

Google also fixed 25 high-severity weaknesses. Most of them are uninitialized resource and use-after-free bugs, two classes of memory safety flaws that regularly appear in browser advisories.

Five high-severity type confusion flaws were patched in V8, the engine that runs JavaScript and WebAssembly code in Chrome. Type confusion in V8 has long drawn attackers' interest, because the engine processes untrusted code from every website a user visits.

The other high-severity issues cover several bug types:

  • improper privilege management
  • UI misconfiguration
  • out-of-bounds read and write
  • cross-site scripting (XSS)
  • buffer overflow

External researchers reported 15 of the patched flaws. Google has not said how much it paid for 14 of them. The only reward listed in the advisory is $1,000 for a low-severity missing authorization bug in the Payments component.

The update is rolling out as Chrome 154.0.8037.92/.93 for Windows and macOS, and as 154.0.8037.92 for Linux. Chrome usually updates itself, but users can trigger the check manually from the "About Google Chrome" page. The fix takes effect only after the browser restarts.

Firefox 157: sandbox escapes and use-after-free bugs

Mozilla's update is the larger of the two. Firefox 157 fixes about 76 vulnerabilities, 38 of them rated high severity. Most of these are use-after-free and sandbox escape bugs.

Sandbox escapes deserve attention. The browser sandbox is designed to contain malicious code that runs inside a web page, so a flaw that lets code break out of it can take an attacker from the browser to the underlying system.

The remaining high-severity issues in Firefox 157 include:

  • incorrect boundary conditions
  • uninitialized memory
  • privilege escalation
  • information disclosure
  • invalid pointer bugs
  • JIT miscompilation

JIT (just-in-time) compilers turn JavaScript into machine code while a page runs. Miscompilation bugs in that step can lead to memory corruption.

Mozilla also backported many of the fixes to its Extended Support Release (ESR) branches, which organisations use for longer-term stability. The relevant versions are Firefox ESR 153.4, 140.17, and 115.42. Admins who run older ESR lines in managed environments should check that they are on these builds.

No reported exploitation, but patch anyway

The advisories do not mention active exploitation. That lowers the urgency compared with a zero-day, but it does not remove the risk. Once browser patches are public, the fixes can be compared with earlier code to work out where the flaws were, and details of memory safety bugs in widely used software rarely stay obscure for long.

Both vendors advise users to install the updates without delay.

Our Take

A combined total of more than 100 fixes in one day is a reminder of how much code sits inside a modern browser, and how much of that code handles untrusted input. The bug classes in this release are not new. Use-after-free, type confusion, uninitialized memory and sandbox escapes appear in advisory after advisory. This suggests that the memory safety problem in large C and C++ codebases is still far from solved, despite years of hardening work by both vendors.

For readers, the practical point is simple: the browser is often the easiest way into a device, and patch speed matters. This week alone has also brought fixes for high-severity TLS flaws in OpenSSL and WolfSSL and an Apple CoreGraphics zero-day, so teams juggling several update cycles should not let browsers slip down the list.

It is worth watching whether technical details or proof-of-concept code for the critical ANGLE bug, CVE-2026-102331, surface in the coming weeks. Organisations running Firefox ESR should also confirm that their managed deployments actually picked up the new builds, rather than assuming automatic updates did the job.