Skip to content
Security & Trust

Chrome, Firefox patch over 100 flaws; neither vendor mentions exploitation

Chrome 154 and Firefox 157 arrived the same day. For managed fleets, the question is how fast devices catch up.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Chrome, Firefox patch over 100 flaws; neither vendor mentions exploitation

AI-generated image for WebPulse. About our images

Key finding

Chrome security defects fixed: 32 (Source: SecurityWeek, reporting on Google's Chrome update (September 30, 2026))

A browser update looks minor. For a company, it can be real work. On Tuesday, Google and Mozilla both announced releases that fix dozens of security flaws. If your IT team manages browsers on staff desktops, someone now has to get these versions onto every machine. That is our inference, not something the sources describe. It is also the part of this story you can influence.

What was released

SecurityWeek reported that the two updates address over 100 vulnerabilities between them. Google's Chrome release fixes 32 security defects. One is rated critical. It is a buffer overflow in a component called ANGLE, tracked as CVE-2026-102331. An outside researcher reported it.

ANGLE is part of Chrome's graphics layer, which helps draw web content on a computer's graphics hardware. A buffer overflow happens when a program writes more data into a block of memory than the block was built to hold.

Google also fixed 25 high-severity weaknesses. Most are uninitialized resource and use-after-free bugs. Five more are type confusion flaws in V8, the engine that runs JavaScript and WebAssembly in Chrome.

Chrome 154 is rolling out as versions 154.0.8037.92/.93 on Windows and macOS. Linux gets 154.0.8037.92.

Mozilla's Firefox 157 carries roughly 76 fixes. About half of them, 38, are rated high severity. Use-after-free and sandbox escape flaws make up most of that group. Firefox 157 is not the only build to get this work. Three extended-support releases, 115.42, 140.17 and 153.4, also received many of these fixes. Extended-support builds are the slower-moving Firefox versions that some organisations choose to stay on.

32
Chrome security defects fixed
Source: SecurityWeek, reporting on Google's Chrome update (September 30, 2026)
~76
Firefox 157 vulnerabilities patched
Source: SecurityWeek, reporting on Mozilla's Firefox 157 (September 30, 2026)
38
High-severity Firefox defects
Source: SecurityWeek, reporting on Mozilla's Firefox 157 (September 30, 2026)

What these bug types mean

Many of the named flaws are memory errors. A use-after-free happens when a program keeps using memory after releasing it. An attacker who can control what fills that space may be able to steer the program. Both vendors list this bug type.

A type confusion is a close cousin. The code treats data as one kind of thing when it is another. SecurityWeek names this class among the Chrome fixes, in V8.

Two bug types appear in the Firefox list. A sandbox escape is a way out of the restricted box that keeps a web page away from the rest of the computer. A JIT miscompilation is a fault in the engine that speeds up JavaScript, which can produce wrong machine code.

Browsers process untrusted content from every site a person visits. That makes them a frequent target of patches.

What the sources do not say

SecurityWeek reports that neither Google nor Mozilla mentions attackers using any of these flaws. That is not a statement that none were used. It means the reporting gives no sign of active attacks.

SecurityWeek adds that users are advised to update as soon as possible. The figures in this article come from its account of the two advisories.

The lesson: for managed fleets, update speed is an internal choice

The vendors have done their part by writing the fixes. The sources do not describe how these updates reach devices. Where IT controls that process, the gap between a fix shipping and a device running it is set inside the company.

The bug types make that gap worth measuring. These are flaws that can let a hostile page do more than it should. A fix only protects a machine once it is installed.

The Firefox detail adds work. Three separate extended-support builds, 115.42, 140.17 and 153.4, each need to be verified. A team on one of them cannot assume the Firefox 157 rollout covers it.

Questions to put to your IT and security team

First: how many hours or days pass before managed desktops run Chrome 154 and Firefox 157, or the matching ESR builds? Ask for the measured number, not the policy.

Second: which devices sit outside that process, such as contractor laptops? Third: does anyone still run an older Firefox ESR line, and who approved that choice?

A browser patch is routine maintenance, and routine maintenance is where discipline shows. The fixes are shipped. What is left is how quickly your own devices install them.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Google.

CVEs in this analysis
CVE-2026-102331
Share this insight