MilikMilik

Chrome and Firefox Race to Patch Critical Flaws

Chrome and Firefox Race to Patch Critical Flaws
Interest|High-Quality Software

Browser security updates are speeding up—and that’s the real story

Browser security updates are recurring releases in which vendors patch vulnerabilities in core components like rendering engines, site isolation logic, and window management, and the accelerating pace of recent Chrome and Firefox security patches reveals how modern vulnerability discovery and disclosure have become continuous, high-volume processes rather than occasional emergency fixes. This month’s wave of Chrome security patches and Firefox critical vulnerabilities is not just another routine update cycle; it is a clear signal that the browser ecosystem is in a permanent, high-speed race against bugs. Chrome 150 fixed 27 security issues, including two critical use-after-free flaws in Ozone and Views that Google’s own engineers discovered first. Mozilla, meanwhile, pushed out patches for two critical Firefox flaws after exploit code was already public. The headline is simple: the more we look, the more we find—and vendors are finally acting at the pace that reality demands.

Chrome and Firefox Race to Patch Critical Flaws

Chrome’s internal bug hunt: more fixes, less time for attackers

The most telling change in Chrome security patches is who is finding the bugs. In the latest Chrome 150 update, version 150.0.7871.114 for Linux and 150.0.7871.114/.115 for Windows and Mac, Google patched 27 vulnerabilities, including two critical use-after-free issues in Ozone and Views that its own team reported internally. Only three of the 27 came from outside researchers, who split USD 3,000 (approx. RM13,800) in bounty rewards. Everything else was uncovered by Google’s security tooling, including AddressSanitizer, libFuzzer, and Control Flow Integrity checks wired into Chrome’s testing pipeline. According to SecurityWeek, Google’s internal discoveries now outpace external submissions, a shift linked to heavier use of AI-assisted fuzzing across Chrome’s codebase. This month also saw another Chrome security update to 150.0.7871.124/.125 across desktop platforms, fixing 15 additional flaws, including more critical use-after-free bugs in Ozone. This is Chrome’s second major security patch in nine days, and part of more than 1,400 vulnerabilities fixed since April. That volume proves the code always had this many issues; what changed is Google’s ability to root them out before attackers do.

Firefox faces public exploit code—and patches before attacks hit

Firefox’s situation looks different but points to the same trend: faster disclosure, faster fixes, and less time for attackers to enjoy their bugs. Mozilla released updates to address two critical Firefox critical vulnerabilities, warning explicitly that exploit code was already available. The issues—CVE-2026-15718, an invalid pointer in the JavaScript WebAssembly component, and CVE-2026-15719, a site isolation flaw in the DOM Navigation component—are now patched in Firefox version 152.0.6. Mozilla stated, “We are aware that exploit code for this is public, however we are not aware of any attacks in the wild abusing this flaw.” That sentence captures the new normal: exploit proof-of-concepts can circulate widely before mass exploitation begins, and browser vendors now aim to land fixes during that short window. From a user standpoint, these Firefox critical vulnerabilities underline that browser security updates are no longer optional housekeeping—they are direct responses to concrete, weaponizable bugs.

Adobe and VMware show the browser patch storm is part of a wider surge

The spike in Chrome and Firefox security patches is not isolated; it fits into a broader month where multiple vendors rushed out fixes for critical flaws. Adobe released security updates for 88 vulnerabilities, including several critical issues in ColdFusion, Commerce, Experience Manager, and Illustrator. ColdFusion alone received fixes for eight critical weaknesses such as path traversal, code injection, and missing authentication for critical functions, all capable of arbitrary code execution or privilege escalation. Adobe Commerce, Magento Open Source, and Experience Manager also saw high-severity bugs fixed, including file upload and server-side request forgery issues. In parallel, Broadcom shipped a patch for a critical authentication bypass in VMware Avi Load Balancer, CVE-2026-47865, which could let a malicious user with network access reach the Avi Control plane. When browser security updates land in the same cycle as Adobe and VMware fixes, it becomes clear this is a systemic trend: more critical flaws discovered, disclosed, and patched across the entire stack in tighter windows.

What this patch cadence means for defenders—and what to do now

The sheer frequency of critical patches indicates two things: vulnerability discovery has become more aggressive and automated, and disclosure timelines are shrinking because vendors accept that hiding bugs is worse than fixing them quickly. Chrome’s four-week release cycle has not changed, yet the number of vulnerabilities found and patched per cycle has grown sharply. Organizations cannot treat browser security updates as low-priority maintenance anymore; they are frontline defenses that must be applied on rhythm. Practically, that means confirming Chrome has updated to at least 150.0.7871.114—or the later 150.0.7871.124/.125 depending on platform—and restarting the browser, because the fix does not take effect until a restart. Users should open chrome://settings/help to verify the version, which also forces Chrome to apply any pending update. Firefox users need to move to 152.0.6. For Adobe and VMware products, administrators should install the latest patches immediately; even though none of the vulnerabilities are marked as actively exploited, attackers are known to weaponize flaws in these products once advisories are public. The takeaway: treat this rapid-fire patch cadence as the baseline, and build your patch management discipline around it.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!