New Chrome 150, Firefox 152 Releases Patch Critical Security Flaws
Google and Mozilla have both shipped new browser updates this week, addressing a batch of critical-severity security flaws in Chrome 150 and Firefox 152.
Mozilla pushed out Firefox 152.0.6 to close two critical-rated security holes, cautioning that working exploit code for both has already surfaced publicly. The two issues are catalogued as CVE-2026-15718 and CVE-2026-15719 — an invalid pointer bug within the "JavaScript: WebAssembly" engine, and a site isolation flaw affecting the "DOM: Navigation" component.
For both issues, Mozilla states that it's aware exploit code has been made public, but has no evidence yet of the flaws being actively exploited in real-world attacks.
Meanwhile, Google's latest Chrome update addresses a total of 15 security issues, headlined by two critical use-after-free bugs found in Ozone, logged as CVE-2026-15764 and CVE-2026-15765.
Beyond those, the update also squashes 12 high-severity bugs spread across several components — Skia, Libyuv, HTML-in-Canvas, Linux Toolkit Theming, V8, Media, GPU, Core, and the UI layer. The flaws involved a mix of uninitialized memory use, heap buffer overflows, weak policy enforcement, poor validation of untrusted input, and additional use-after-free conditions.
"Of the vulnerabilities addressed, only three were flagged by outside security researchers, with Google's own teams uncovering the remainder internally. As is typical, the company has not yet revealed how much it paid out in bug bounty rewards for these findings. Notably, Google has not indicated that any of these flaws were being exploited before the patches rolled out. The updated browser is now available as versions 150.0.7871.124/.125 for both Windows and macOS users, while Linux users will receive it as version 150.0.7871.124."