Chrome and Firefox releases close over a hundred security holes

Google and Mozilla pushed new builds fixing 32 Chrome flaws and roughly 76 Firefox bugs in a single day of browser patching.

CSBadmin
2 Min Read

Separate updates from Google and Mozilla on September 29 tidy up more than 100 browser vulnerabilities between them, splitting the work across two very different codebases.

Chrome’s batch covers 32 defects. The most serious is a critical buffer overflow inside ANGLE, the graphics layer, filed as CVE-2026-102331 and credited to an outside researcher. Beyond that, Google closed 25 high-severity bugs that lean on uninitialized-resource and use-after-free weaknesses, plus five type-confusion problems in V8, the JavaScript and WebAssembly engine. Rounding out the notes are improper privilege management, out-of-bounds reads and writes, cross-site scripting and more buffer overflows.

Windows and macOS users are receiving builds 154.0.8037.92 and .93, while the Linux build arrives as 154.0.8037.92 on its own.

Over at Mozilla, Firefox 157 lands with roughly 76 fixes, 38 of them rated high severity and mostly use-after-free plus sandbox-escape bugs. The advisory also folds in JIT miscompilation, invalid pointers and privilege escalation. Its tally further names incorrect boundary conditions, uninitialized memory and information disclosure among the resolved issues.

The identical set of patches reaches the ESR line as well: Firefox ESR 153.4, 140.17 and 115.42.

Neither company says any of the flaws have been attacked in the wild, yet both tell users to move quickly. Endpoint teams should get the new builds out before the next patch window opens.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.