ZeroHour
Product

Thunderbird

1 mentions in 7 days · 1 in 30 days · 2 total · first seen · last

Timeline

Chrome, Firefox Updates Patch 115 Vulnerabilities

Google and Mozilla patch 115 vulnerabilities across Chrome 153 and Firefox 156, including three critical Chrome bugs; no exploitation reported.

Google's Chrome 153 (153.0.8010.47/.48 for Windows/macOS) fixes 42 flaws, including three critical: CVE-2026-91726, an out-of-bounds read in WebGL, and use-after-free bugs CVE-2026-91721 and CVE-2026-91749 in Internals and Workers. Mozilla's Firefox 156 resolves 73 vulnerabilities, including 29 high-severity use-after-free and privilege escalation issues, with related fixes in Thunderbird and Firefox ESR branches. Neither vendor reports any of the defects being exploited in the wild.

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla revoked the Firefox and Thunderbird Linux RPM signing subkey after an unencrypted copy landed in a private repo; no unauthorized access found.

Mozilla revoked the OpenPGP signing subkey (fingerprint 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256) used for Firefox and Thunderbird Linux downloads after an unencrypted copy was committed to one of its private repositories, citing reason code 2, 'key material has been compromised.' Audit records showed no sign of unauthorized access, and a replacement subkey (827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3) valid until August 5, 2028 was published. Users who verify signatures manually or install from Mozilla RPM packages may need to import the new key and remove the old one. The rotation came roughly seven months ahead of Mozilla's usual two-year subkey cycle.

The Hacker News · Aug 11, 2026Data breach

Related CVEs

  • Critical Use-After-Free in Google Chrome Workers Enables Sandbox Escape
    CVE-2026-91749 is a critical-severity use-after-free vulnerability (CWE-416) in the Workers component of Google Chrome, fixed in version 153.0.8010.47. A remote attacker triggers the flaw by luring a victim to a crafted HTML page, where a freed memory object in the Worker implementation is improperly reused, potentially allowing arbitrary code execution outside the browser sandbox. Successful exploitation means a malicious webpage can escape Chrome's sandbox and run code on the underlying operating system with the user's privileges, effectively fully compromising the workstation. All Chrome installations prior to 153.0.8010.47 are affected on every platform, and third-party Chromium-based browsers inherit the vulnerable engine code until they ship the upstream fix. No public proof-of-concept is known and the bug is not on CISA's Known Exploited Vulnerabilities catalog, but the Critical severity rating indicates Google judged the potential impact to be severe.
    · Google Chrome < 153.0.8010.47mass
  • Use-After-Free Allowing Sandbox Escape RCE in Google Chrome Before 153.0.8010.47
    CVE-2026-91721 is a critical use-after-free flaw (CWE-416) in Chrome's Internals component affecting versions prior to 153.0.8010.47. A remote attacker triggers it by convincing a user to visit a crafted HTML page, which corrupts freed memory and can lead to arbitrary code execution outside the browser sandbox — a full compromise of the victim's machine rather than a sandboxed renderer compromise. The issue carries a CVSS 3.1 score of 8.8 (network vector, low complexity, no privileges, but user interaction required) and was rated Critical by the Chromium security team. All users of Google Chrome on any platform who have not updated to 153.0.8010.47 or later are affected, with downstream Chromium-based browsers potentially inheriting the flaw. No public proof of concept is known and the vulnerability is not listed in CISA's KEV catalog, so no in-the-wild exploitation has been confirmed at this time.
    · Google Chrome < 153.0.8010.47mass
  • Out-of-Bounds Read in WebGL Enables Sandbox Escape in Chrome on Android
    CVE-2026-91726 is an out-of-bounds read (CWE-125) in the WebGL implementation of Google Chrome on Android, fixed in version 153.0.8010.47. A remote attacker triggers the flaw by convincing a user to visit a crafted HTML page, which causes the browser to read memory outside of Chrome's sandbox. Although the CVSS 3.1 base score is 4.7 (medium) due to the requirement for user interaction and limited confidentiality-only impact, Google's Chromium team rates it Critical because defeating the sandbox boundary undermines Chrome's core security model. Only Chrome on Android versions prior to 153.0.8010.47 are affected; desktop and other-platform Chrome builds are not in scope per the advisory. There is no known public proof of concept, the CVE is not on CISA's KEV list, and no exploitation in the wild has been reported; the flaw was patched as one of three critical issues in the Chrome 153 update.
    · Google Chrome (Android) < 153.0.8010.47mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.