Chrome, Firefox Patch Over 100 Flaws in Joint Update

Chrome and Firefox fixed over 100 vulnerabilities between them, including a critical ANGLE buffer overflow in Chrome rated capable of remote code execution.
Table of Contents
    Add a header to begin generating the table of contents

    Google and Mozilla released browser updates patching more than 100 combined vulnerabilities, led by a critical buffer overflow in Chrome’s ANGLE graphics component that the company rated capable of remote code execution.

    Chrome’s Critical ANGLE Flaw Headlines 32 Fixes

    Chrome’s update, shipped in versions 154.0.8037.92 and .93, fixes 32 vulnerabilities in total. The most severe is CVE-2026-102331, a critical-severity buffer overflow in ANGLE, the graphics abstraction layer Chrome uses to translate rendering calls across different hardware and operating systems. Because ANGLE sits between web content and the underlying graphics driver, a buffer overflow there can potentially be reached simply by rendering attacker-controlled graphics content in a page, which is part of why Google rated the flaw as capable of remote code execution rather than a more limited crash or information leak. The same release also addresses 25 additional high-severity issues alongside the critical ANGLE bug.

    Firefox’s Update Clears Roughly 76 Flaws, Many Use-After-Free Bugs

    Mozilla’s Firefox update, version 157, along with extended support releases 153.4, 140.17, and 115.42, fixes approximately 76 vulnerabilities. Thirty-eight of those are rated high-severity, and Mozilla’s advisory indicates most of them are use-after-free and sandbox-escape-class bugs — defect categories that, when exploitable, can let attacker-controlled code break out of the browser’s security sandbox and interact with the broader operating system.

    No Evidence of In-the-Wild Exploitation for Either Browser

    Neither Google nor Mozilla disclosed any evidence that attackers are actively exploiting the vulnerabilities patched in these releases. For Chrome specifically, Google disclosed only limited bug-bounty payout information this round: $1,000 for one low-severity issue, with 14 other researcher rewards left undisclosed at the time of the update’s release.

    Updates Deploy Automatically Through Standard Channels

    Both vendors are directing users toward their standard auto-update mechanisms rather than requiring any manual download or configuration change, and both have recommended that users and administrators confirm their installations have applied the latest versions rather than assuming the update happened silently in the background.

    Why Volume Alone Makes This Update Cycle Consequential

    A combined total exceeding 100 patched vulnerabilities across the two most widely used desktop browsers represents a broad reduction in available attack surface, even though none of the individual flaws has a confirmed history of exploitation at the time of patching. Browser vulnerabilities occupy a specific position in the overall threat landscape: unlike a server-side flaw that requires an attacker to reach a specific exposed service, a browser bug can potentially be triggered simply by getting a target to visit a malicious or compromised webpage, which is part of why use-after-free and sandbox-escape bugs in particular tend to draw sustained attacker interest once their technical details become public.

    ANGLE’s Critical Flaw and Automatic Updates Across Both Browsers

    That dynamic is why the absence of confirmed in-the-wild exploitation at disclosure time should not be read as an indication that the patched flaws are low-risk going forward. Proof-of-concept exploit code for browser vulnerabilities has historically circulated within days or weeks of a patch becoming public, as researchers and attackers alike reverse-engineer the fix to understand exactly what was broken and how. Chrome’s combined global market share with Firefox means a meaningful share of all web traffic worldwide runs through one of the two browsers patched in this cycle, and the specific presence of a critical, RCE-capable buffer overflow in a component as foundational as ANGLE gives this particular update cycle a higher urgency than a routine maintenance release, regardless of the current absence of exploitation evidence. Automatic updates will cover most consumer users without any action required, but enterprise environments that manage browser deployment through group policy or delayed-rollout channels should confirm the update has actually propagated rather than assuming it has.

    The gap between Chrome and Firefox’s disclosed bug-bounty figures also marks a difference in disclosure transparency. Mozilla’s advisory characterized the bulk of its high-severity fixes by vulnerability class — use-after-free and sandbox-escape — giving defenders a clearer sense of what kind of exploitation technique each fix forecloses, while Google’s decision to withhold payout details for 14 of 15 rewarded reports this round limits how much outside researchers and defenders can infer about which of the 32 Chrome fixes were considered most severe by the company’s own bounty program, beyond the single critical ANGLE flaw it did name directly.

    Related Posts