www.securityweek.com 16 Sept 2026, 10:28 UTC

Google and Mozilla Patch 115 Browser Flaws Including Critical Bugs

Google and Mozilla Patch 115 Browser Flaws Including Critical Bugs
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

GOOGLE and Mozilla have issued browser security updates addressing 115 vulnerabilities in total. Chrome 153 fixes 42 defects, including three critical issues: CVE-2026-91726, an out-of-bounds read in WebGL, and CVE-2026-91721 and CVE-2026-91749, use-after-free vulnerabilities in Internals and Workers. The release also addresses high-severity use-after-free, race-condition, type-confusion, integer-overflow, incorrect-authorisation and uninitialised-resource flaws.

Google said external researchers reported 16 of the vulnerabilities; only two bug-bounty payments, totalling $2,500, have been disclosed. Chrome 153.0.8010.47/.48 is rolling out for Windows and macOS, while Linux users are receiving 153.0.8010.47.

Mozilla’s Firefox 156 release fixes 73 vulnerabilities, including 29 rated high severity. Most involve use-after-free and privilege-escalation problems, alongside sandbox escape, site-isolation, incorrect-boundary-condition and mitigation-bypass weaknesses. Mozilla listed individual memory-safety issues separately rather than grouping internally identified flaws under a single CVE, accounting for the larger number of listed vulnerabilities.

Many of the fixes also apply to Thunderbird 156 and 140.16, and Firefox ESR 153.3, 140.16 and 115.41. Neither company reported exploitation of these vulnerabilities in the wild, but users are advised to install the relevant updates as soon as possible.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline