All stories

Public exploits for Firefox critical vulnerabilities drive urgent browser security updates

Mozilla has released patches for two critical Firefox vulnerabilities that already have public exploit code available. While no active attacks in the wild have been confirmed, defenders should update their browsers immediately to mitigate risk. Google has also issued a significant update for Chrome to address 15 total vulnerabilities, including several high-severity flaws.

Summary

Mozilla and Google have released urgent updates to resolve multiple security defects across their respective web browsers. Mozilla's latest release targets two critical-severity bugs in Firefox that are already accompanied by public exploit code. Simultaneously, Google has addressed a broader range of issues in Chrome, including two critical use-after-free vulnerabilities within the Ozone component and 12 high-severity bugs affecting various browser subsystems such as V8, Skia, and GPU.

Firefox Critical Vulnerabilities

Mozilla released Firefox 152.0.6 to address two specific security defects classified as critical. The first, CVE-2026-15718, involves an invalid pointer within the 'JavaScript: WebAssembly' component. The second, CVE-2026-15719, is a site isolation issue located in the 'DOM: Navigation' component.

Mozilla has confirmed that exploit code for both weaknesses is currently public. Despite the availability of these exploits, the company stated they are not aware of any attacks in the wild abusing these specific flaws.

Chrome Vulnerability Breakdown

The latest Google Chrome update addresses a total of 15 vulnerabilities. Two of these are classified as critical use-after-free flaws found in Ozone: CVE-2026-15764 and CVE-2026-15765.

Beyond the critical issues, the update resolves 12 high-severity bugs spanning several core components of the browser. These include:

  • Skia
  • Libyuv
  • HTML-in-Canvas
  • Linux Toolkit Theming
  • V8
  • Media
  • GPU
  • Core
  • UI

The high-severity flaws involve various memory and input validation issues, specifically uninitialized use, heap buffer overflow, insufficient policy enforcement, insufficient validation of untrusted input, and additional use-after-free vulnerabilities. While Google has not reported any active exploitation of these bugs, the breadth of affected components suggests a wide attack surface.

Affected products and fixed versions

Browser Fixed Version OS Support
Firefox 152.0.6 All supported platforms
Chrome (Windows) 150.0.7871.124/.125 Windows
Chrome (macOS) 150.0.7871.124/.125 macOS
Chrome (Linux) 150.0.7871.124 Linux

Defender guidance

Prioritize updating Firefox first due to the confirmed existence of public exploit code for critical flaws. For organizations managing large fleets of browsers, ensure that Chrome versions are bumped to at least 150.0.7871.124 across all operating systems to mitigate the risk from the 15 identified vulnerabilities.

Sources

  1. https://www.securityweek.com/critical-vulnerabilities-patched-with-fresh-chrome-150-firefox-152-updates/
  2. https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -