Chrome 152 and Firefox 155 Patch Dozens of Flaws

Google and Mozilla released Chrome 152 and Firefox 155 with fixes for dozens of vulnerabilities, including two critical use-after-free bugs in Chrome and 13 high-severity issues in Firefox.

Google and Mozilla released security updates on Tuesday for their Chrome and Firefox browsers that address dozens of vulnerabilities across Windows, macOS, Linux and Android.

Google distributed Chrome 152 with fixes for 26 security flaws. Two critical use-after-free vulnerabilities are listed with CVE-2026-84353 affecting Shared Tab Groups and CVE-2026-84352 affecting WebGL. The update corrects nine high-severity defects involving use-after-free, incorrect authorization, information leaks, improper input validation, uninitialized resources and a buffer overflow. The remaining 15 issues are rated medium or low severity. Chrome 152 is rolling out as versions 152.0.7977.75 and 152.0.7977.76 for Windows and macOS, and 152.0.7977.75 for Linux. Google’s advisory notes that three of the flaws were reported by external researchers and no bug bounty reward is disclosed.

Mozilla released Firefox 155 with patches for 29 security defects, including 13 high-severity issues that include use-after-free, sandbox escape and memory corruption vulnerabilities. The fixes affect several components, including the garbage collector, navigation code, audio and video handling, WebGPU, core HTML processing and the Grid layout engine. Firefox for Android receives the same set of fixes. Mozilla’s release states that three CVEs cover multiple related bugs that can lead to memory corruption and could have been exploitable with sufficient effort.

Mozilla also issued updates for extended support and mail clients: Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15 and Thunderbird 153.2, each including the same security fixes. Neither Google nor Mozilla reports that any of the patched vulnerabilities are known to have been exploited in active attacks.

Use-after-free flaws occur when software accesses memory after it has been released, which can allow attackers to crash a program or run arbitrary code. Sandbox escape vulnerabilities let malicious code break out of a restricted environment. Memory corruption can alter program state and enable further exploits.

Both vendors recommend applying the updates promptly. Chrome and Firefox normally distribute patches via built-in update mechanisms; users should ensure automatic updates are enabled or check for the new versions manually. System administrators should prioritize patching managed devices and confirm ESR and Thunderbird updates in enterprise deployments.

Articles by this author