Chrome, Firefox patches fix over 100 security flaws

Chrome 154 and Firefox 157 patch over 100 security flaws: Chrome fixes 32, including a critical ANGLE buffer overflow (CVE-2026-102331); Firefox fixes about 76, including 38 high-severity bugs.

Google and Mozilla released Chrome 154 and Firefox 157 on Tuesday, installing fixes for more than 100 security vulnerabilities. Chrome’s update is rolling out as versions 154.0.8037.92/.93 for Windows and macOS and 154.0.8037.92 for Linux.

Chrome 154 closes 32 security flaws. The list includes a critical buffer overflow in the ANGLE graphics layer tracked as CVE-2026-102331 and reported by an external researcher. The release also corrects 25 high-severity issues, mostly uninitialized resource and use-after-free bugs, and five high-severity type confusion flaws in the V8 JavaScript and WebAssembly engine. Other fixes address improper privilege management, UI misconfiguration, out-of-bounds read/write, cross-site scripting and additional buffer overflows. External researchers reported 15 of the patched flaws. Google’s advisory notes a $1,000 bounty paid for a low-severity missing authorization bug in Payments; bounty amounts for 14 other reports were not disclosed.

Firefox 157 includes patches for about 76 vulnerabilities, 38 of them rated high severity. The most serious fixes cover use-after-free and sandbox escape bugs. The update also resolves incorrect boundary conditions, uninitialized memory, privilege escalation, information disclosure, invalid pointer handling and just-in-time compilation errors. Mozilla backported many of the same fixes to Firefox Extended Support Release versions 153.4, 140.17 and 115.42.

Neither Google’s nor Mozilla’s advisories list active exploitation of the patched flaws. The fixes are available through each browser’s standard update mechanism and can be installed by users and system administrators.

ANGLE is a translation layer that maps WebGL and other browser graphics calls to native graphics APIs. V8 is Chrome’s engine for executing JavaScript and WebAssembly code. Firefox ESR releases provide longer-term maintenance for organizations, which is why several fixes were included in multiple ESR updates.

Both vendors publish security advisories with technical summaries and vulnerability counts. The updates follow routine reporting and disclosure processes in which external researchers and internal teams identify issues and vendors validate and ship fixes to users.

Articles by this author