Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Google and Mozilla patched more than 100 Chrome and Firefox flaws, including critical CVE-2026-102331, with no known exploitation.
Google's Chrome 154.0.8037.92/.93 fixes 32 vulnerabilities, including critical ANGLE buffer overflow CVE-2026-102331, 25 high-severity issues, and five high-severity V8 type-confusion flaws. Mozilla's Firefox 157 patches about 76 vulnerabilities, 38 of them high severity, with many also fixed in Firefox ESR 153.4, 140.17, and 115.42. Neither vendor reports in-the-wild exploitation.
- Chrome 154 fixes 32 bugs, including critical CVE-2026-102331 in ANGLE.
- Twenty-five Chrome issues are high severity, including five V8 type-confusion flaws.
- Firefox 157 fixes about 76 vulnerabilities, 38 rated high severity.
- Neither vendor reports these flaws exploited in the wild.
Vulnerabilities mentionedAll →
- CVE-2026-1023319.6—Heap Buffer Overflow in ANGLE Graphics Layer in Google Chrome for Android (<154.0.8037.92)published · Google Chrome for Android
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102331 | Heap Buffer Overflow in ANGLE Graphics Layer in Google Chrome for Android (<154.0.8037.92) This is a heap-based buffer overflow (CWE-122) in ANGLE, the graphics translation layer Chrome uses to render WebGL and GPU-accelerated content, affecting Google Chrome on Android prior to version 154.0.8037.92. A remote attacker triggers it by convincing a victim to visit a crafted HTML page, where malicious graphics-related content corrupts memory in the ANGLE code path. Successful exploitation can yield arbitrary code execution outside the Chrome sandbox, meaning the compromise is not contained to the renderer process. All users of Chrome on Android who have not updated to 154.0.8037.92 or later are affected; desktop and other platform builds are not named in this advisory. There is no known public proof of concept and no indication of in-the-wild exploitation, though the critical severity and drive-by nature of the trigger warrant prompt patching. |
Full article291 words · extracted from securityweek.com · click to collapse
Google and Mozilla on Tuesday announced fresh Chrome and Firefox updates that address over 100 vulnerabilities.
The latest Chrome release was rolled out with fixes for 32 security defects, including a critical-severity buffer overflow issue in ANGLE tracked as CVE-2026-102331 and reported by an external researcher.
Google addressed 25 high-severity security weaknesses, most of which are uninitialized resource and use-after-free vulnerabilities. It also resolved five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine.
The browser update also fixes high-severity improper privilege management, UI misconfiguration, out-of-bounds read/write, cross-site scripting (XSS), and buffer overflow issues.
External researchers reported 15 of the patched security holes, but Google has not disclosed the bounty rewards paid for 14 of them. According to its advisory, the company handed out $1,000 for a low-severity missing authorization bug in Payments.
The latest Chrome iteration is now rolling out to users as versions 154.0.8037.92/.93 for Windows and macOS, and as version 154.0.8037.92 for Linux.
Advertisement. Scroll to continue reading.
Mozilla released Firefox 157 with patches for approximately 76 vulnerabilities, including 38 high-severity security defects, mostly use-after-free and sandbox escape bugs.
The fresh Firefox update also resolves high-severity incorrect boundary conditions, uninitialized memory, privilege escalation, information disclosure, invalid pointer, and JIT miscompilation issues.
Many of the vulnerabilities resolved in Firefox 157 were also fixed in Firefox ESR 153.4, 140.17, and 115.42.
Google and Mozilla make no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible.
Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Related: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Related: Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability