MilikMilik

Chrome, Firefox and Adobe Rush Out Critical Fixes—Update Now

Chrome, Firefox and Adobe Rush Out Critical Fixes—Update Now
Interest|High-Quality Software

This Patch Cycle Is Not Routine—It’s a Red Alert for Everyday Users

This security advisory covers a coordinated wave of browser security updates and software vulnerabilities fixes in Chrome, Firefox, Adobe products, and VMware, explaining why several newly patched flaws are critical, how they could let attackers hijack systems, and what concrete steps users and organizations must take to update safely and reduce exposure to known bugs. The key takeaway is blunt: if you browse the web, build sites, or run ColdFusion and VMware infrastructure, this is one of those weeks where postponing updates is a poor security choice rather than a harmless delay. Google’s latest Chrome 150 release patches 27 vulnerabilities, including two critical use-after-free flaws that could allow an attacker to hijack the browser’s window management logic. Mozilla’s Firefox update fixes two critical issues where exploit code is already public. Adobe, meanwhile, has shipped 88 security updates spanning ColdFusion, Commerce, Experience Manager, and Illustrator, with several bugs rated at the highest severity. Taken together, this is not background noise—it is a direct challenge to how seriously you treat browser and app updates.

Chrome’s Aggressive Self-Testing Shows How Messy Modern Browsers Really Are

The most striking part of the latest Chrome security patches isn’t just the 27 bugs fixed, but who found them. In version 150.0.7871.114, Google’s own engineers discovered both critical vulnerabilities—a pair of use-after-free flaws in Ozone and Views, components that sit close to how Chrome renders and manages windows. That proximity is why these defects carry a critical rating: corrupting memory near the windowing system can translate quickly into full browser compromise. Only three of the 27 fixes in this update came from external researchers, who split USD 3,000 in bounty rewards. Everything else came from Google’s internal toolchain, including AddressSanitizer, libFuzzer, and Control Flow Integrity checks built into Chrome’s testing pipeline. According to SecurityWeek, Google’s internal discoveries have outpaced outside bug bounty submissions for months, a shift linked to more aggressive AI-assisted fuzzing across Chrome’s codebase. That quote tells a story: "Since April, Google says it has fixed more than 1,400 Chrome vulnerabilities, and the updates released in June and July alone accounted for over 1,000 of those fixes." The pace—382 vulnerabilities patched in the June 30 update with 15 critical issues—shows how complex and fragile browser internals have become.

Chrome, Firefox and Adobe Rush Out Critical Fixes—Update Now

Firefox’s Public Exploit Code and Adobe’s Enterprise Exposure Raise the Stakes

If Chrome’s volume of vulnerabilities hints at structural complexity, Firefox’s latest issues highlight a more immediate concern: proof-of-concept attack code is out in the open. Mozilla’s new release addresses two critical flaws, CVE-2026-15718 (an invalid pointer in the JavaScript WebAssembly component) and CVE-2026-15719 (a site isolation weakness in DOM navigation). Mozilla’s own advisory bluntly notes, "We are aware that exploit code for this is public, however we are not aware of any attacks in the wild abusing this flaw." These bugs are fixed in Firefox 152.0.6, and staying on a previous version means staying exposed by choice. Adobe’s situation affects deeper infrastructure. Security updates cover 88 vulnerabilities, including multiple critical bugs in ColdFusion, Commerce, Experience Manager, and Illustrator. ColdFusion alone has eight high-impact issues, such as path traversal, code injection, improper input validation, incorrect authorization, missing authentication, and SQL injection—all of which can lead to arbitrary code execution or privilege escalation. These ColdFusion flaws are remediated in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22. If your stack relies on ColdFusion or Adobe Commerce, this patch cycle touches systems that attackers historically treat as lucrative targets, not side projects.

VMware and Ongoing Chrome Fixes Underscore That No Layer Is Immune

Beyond the headline browsers and creative apps, the same update window includes infrastructure-grade problems. Broadcom has released a fix for a critical authentication bypass vulnerability in VMware Avi Load Balancer (CVE-2026-47865, CVSS 9.8), where a malicious user with network access can jump straight into the Avi Control plane. That is not a theoretical concern; control planes are usually where administrators configure everything else, so compromise there can cascade across an environment. Chrome itself continues to receive additional security patches in the same family of releases. Separate fixes cover 15 security flaws, including two further critical use-after-free bugs in the Ozone component (CVE-2026-15764 and CVE-2026-15765). These issues affect Chrome on Linux and are patched in version 150.0.7871.124 for Linux and 150.0.7871.124/.125 for Windows and Mac. A description from the NVD makes the situation plain: "Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page." In other words, a normal browsing session, plus one malicious page, can become the start of a full compromise.

What You Should Do Today: Concrete Update Steps and a Mindset Shift

Given the breadth of these browser security updates and software vulnerabilities fixes, the correct response is intentional, not panicked. Although none of the vulnerabilities have been marked as actively exploited, organizations are urged to install the latest updates, because threat actors are known to weaponize flaws in these products. For Chrome, confirm that updates are installed and applied: Chrome brings in the 150.0.7871.114 update automatically in the background, but the fix does not take effect until the browser restarts. Open chrome://settings/help to confirm the version number, and Chrome will finish applying any pending update when that page loads. For Firefox, upgrade to version 152.0.6 immediately, since the two critical flaws already have public exploit code. For Adobe ColdFusion, move to ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22; for Adobe Commerce and Experience Manager, apply the latest vendor patches covering the listed CVEs. For VMware Avi Load Balancer, deploy Broadcom’s fix for CVE-2026-47865 without waiting for a broader maintenance window. The conclusion is plain: treating updates as optional is a holdover from a quieter era. Modern browsers and creative stacks are large attack surfaces in constant motion, and this patch cycle is a reminder that staying safe is less about strong opinions on security and more about doing the boring work of updating on time.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!