www.securityweek.com 30 Sept 2026, 12:16 UTC

Chrome and Firefox Fix More Than 100 Flaws, Including Critical Bug

Chrome and Firefox Fix More Than 100 Flaws, Including Critical Bug
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

GOOGLE and Mozilla released Chrome and Firefox updates addressing more than 100 vulnerabilities. Chrome’s September 2026 update fixes 32 security defects, including a critical-severity buffer overflow in ANGLE tracked as CVE-2026-102331, reported by an external researcher.

The Chrome roll-out covers 25 high-severity issues—predominantly uninitialized resources and use-after-free flaws in the browser core and V8/WebAssembly components—and also resolves high-severity problems related to improper privilege management, UI misconfiguration, out-of-bounds read/write, cross-site scripting and buffer overflows. Chrome versions are 154.0.8037.92 and 154.0.8037.93 for Windows and macOS, with Linux receiving 154.0.8037.92.

Mozilla followed with Firefox 157, addressing around 76 vulnerabilities, including 38 high-severity defects. Many fixes target use-after-free and sandbox-escape issues, along with high-severity problems tied to incorrect boundary conditions, uninitialized memory, privilege escalation, information disclosure, invalid pointers and JIT miscompilation. Several of the Firefox fixes also appear in the ESR tracks: Firefox ESR 153.4, 140.17 and 115.42. Neither Google nor Mozilla disclosed exploitation in the wild for these defects, but users are urged to update promptly.

Evidence in the advisory notes external researchers contributed to reporting some of the Chrome flaws, and Google and Mozilla provide details on CVEs and affected components. The article does not indicate active exploitation, but the scale of fixes across both browsers underscores the importance of applying updates to mitigate potential remote code execution and sandbox-escape risks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline