Chrome and Firefox updates fix more than 100 flaws
Google and Mozilla patched more than 100 Chrome and Firefox flaws, including critical CVE-2026-102331, with no reported exploitation.
On September 29, 2026, the Canadian Centre for Cyber Security issued advisory AV26-976 urging updates for Firefox versions before 157 and Firefox ESR versions before 153.4, 140.17, and 115.42. That notice names no CVE identifiers and does not report active exploitation. SecurityWeek reported on September 30 that Mozilla's Firefox 157 patches about 76 vulnerabilities, 38 of them high severity, with many also fixed in those same ESR branches. Google's Chrome 154.0.8037.92/.93 fixes 32 vulnerabilities, including critical ANGLE buffer overflow CVE-2026-102331, 25 high-severity issues, and five high-severity V8 type-confusion flaws. Together the vendors patched more than 100 flaws, and neither reports in-the-wild exploitation. The sources differ in scope: the Canadian advisory covers only Firefox and names no CVEs, while SecurityWeek adds Chrome counts and CVE-2026-102331.
- On September 29, 2026, the Canadian Centre for Cyber Security issued advisory AV26-976 for Firefox before 157 and Firefox ESR before 153.4, 140.17, and 115.42.
- The Canadian bulletin names no CVE identifiers and does not report active exploitation.
- Firefox 157 patches about 76 vulnerabilities, 38 rated high severity, with many also fixed in ESR 153.4, 140.17, and 115.42.
- Chrome 154.0.8037.92/.93 fixes 32 vulnerabilities, including critical ANGLE buffer overflow CVE-2026-102331.
- Twenty-five Chrome issues are high severity, including five high-severity V8 type-confusion flaws.
- Neither Google nor Mozilla reports these flaws exploited in the wild.
- Together the Chrome and Firefox updates address more than 100 vulnerabilities.
Coverage timelineoldest first · each row is one article
- · 1d agoMozilla security advisory (AV26-976)
Canadian Centre for Cyber Security· 34
Canada's Cyber Centre urges updates for Firefox before 157 and three Firefox ESR branches after Mozilla security fixes.
- · 9h agoChrome, Firefox Updates Patch Over 100 Vulnerabilities
SecurityWeek· 68
Google and Mozilla patched more than 100 Chrome and Firefox flaws, including critical CVE-2026-102331, with no known exploitation.
Vulnerabilities in this storyAll →
- CVE-2026-1023319.6—Heap Buffer Overflow in ANGLE Graphics Layer in Google Chrome for Android (<154.0.8037.92)published · Google Chrome for Android
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-102331 | Heap Buffer Overflow in ANGLE Graphics Layer in Google Chrome for Android (<154.0.8037.92) This is a heap-based buffer overflow (CWE-122) in ANGLE, the graphics translation layer Chrome uses to render WebGL and GPU-accelerated content, affecting Google Chrome on Android prior to version 154.0.8037.92. A remote attacker triggers it by convincing a victim to visit a crafted HTML page, where malicious graphics-related content corrupts memory in the ANGLE code path. Successful exploitation can yield arbitrary code execution outside the Chrome sandbox, meaning the compromise is not contained to the renderer process. All users of Chrome on Android who have not updated to 154.0.8037.92 or later are affected; desktop and other platform builds are not named in this advisory. There is no known public proof of concept and no indication of in-the-wild exploitation, though the critical severity and drive-by nature of the trigger warrant prompt patching. |