Critical Security Updates: Chrome and Firefox Patch 115 Vulnerabilities
Google and Mozilla have issued critical security updates for their respective browsers, resolving a combined total of 115 vulnerabilities.
Chrome 153 Security Updates
The Chrome 153 release addresses 42 security issues, including three critical-severity flaws and 28 high-severity bugs. Among the critical vulnerabilities is CVE-2026-91726, an out-of-bounds read vulnerability in WebGL. Two additional critical flaws, CVE-2026-91721 and CVE-2026-91749, involve use-after-free conditions in the Internals and Workers components, respectively. The update also resolves high-severity issues such as use-after-free, race conditions, type confusion, integer overflows, incorrect authorization, and uninitialized resource weaknesses.
Critical Vulnerabilities in Chrome 153
The Chrome 153 release addresses 42 security issues, including three critical-severity flaws and 28 high-severity bugs. Among the critical vulnerabilities is CVE-2026-91726, an out-of-bounds read vulnerability in WebGL. Two additional critical flaws, CVE-2026-91721 and CVE-2026-91749, involve use-after-free conditions in the Internals and Workers components, respectively.
High-Severity Issues in Chrome 153
The update also resolves high-severity issues such as use-after-free, race conditions, type confusion, integer overflows, incorrect authorization, and uninitialized resource weaknesses. Of the 42 patched vulnerabilities, 16 were reported by external researchers, though Google has not disclosed the full amounts of bug bounty payments. Only two rewards totaling $2,500 were publicly confirmed.
Bug Bounty and Update Availability
The Chrome 153 update is now available as versions 153.0.8010.47/.48 for Windows and macOS, and 153.0.8010.47 for Linux.
Firefox 156 Security Updates
Mozilla’s Firefox 156 update addresses 73 vulnerabilities, including 29 high-severity flaws. The majority of these high-severity issues involve use-after-free and privilege escalation vulnerabilities, alongside sandbox escape, site isolation, incorrect boundary condition, and mitigation bypass flaws.
High-Severity Vulnerabilities in Firefox 156
Mozilla’s Firefox 156 update addresses 73 vulnerabilities, including 29 high-severity flaws. The majority of these high-severity issues involve use-after-free and privilege escalation vulnerabilities, alongside sandbox escape, site isolation, incorrect boundary condition, and mitigation bypass flaws.
Tracking Vulnerabilities in Firefox
This release marks a shift from previous Mozilla advisories, which grouped memory safety issues under a single CVE. Instead, each vulnerability is now individually tracked, contributing to the higher count of CVE identifiers.
Additional Fixes and Recommendations
Additional fixes were included in the latest Thunderbird 156 and 140.16 releases, as well as Firefox ESR versions 153.3, 140.16, and 115.41. Neither Google nor Mozilla has confirmed active exploitation of the patched vulnerabilities, but users are strongly encouraged to apply the updates promptly.
Industry Trends and Recommendations
The Chrome 153 and Firefox 156 updates follow broader industry trends of frequent security patching, with other recent advisories highlighting exploits targeting WSO2, Oracle, and third-party software. Enterprises are advised to prioritize browser updates to mitigate risks associated with unpatched vulnerabilities.
