Full Breakdown
Major Browser Updates Patch Hundreds of Critical Flaws
7/16/2026, 12:11:58 PM
Core Event: Google Chrome 150 and Mozilla Firefox 152 Receive Critical Security Patches
In July 2026 Google released Chrome 150 (build 150.0.7871.124/125 for Windows and macOS, 150.0.7871.124 for Linux) and Mozilla released Firefox 152.0.6 (July 14) to remediate a large set of high-severity vulnerabilities. The updates address critical use-after-free, memory-corruption, sandbox-escape and privilege-escalation bugs, including CVE-2026-15764, CVE-2026-15765 in Chrome’s Ozone layer and CVE-2026-15718, a JavaScript WebAssembly flaw in Firefox for which public exploit code has been published.
Background & Context: Ongoing Vulnerability Landscape
Both browsers are frequent targets because they process vast amounts of web traffic and store sensitive data. Earlier in June, Mozilla’s June 16 release of Firefox 152 fixed over 40 vulnerabilities, while Google’s late-June Chrome 150 release patched 433 flaws. The rapid succession of patches reflects a broader industry trend of accelerated discovery and disclosure of memory-safety bugs in browser components such as Dawn, ANGLE, Skia, Ozone and WebRender.
Data & Statistics: Scope of Fixed Vulnerabilities
- Chrome 150 addresses 382 vulnerabilities in its public advisory, including 15 classified as critical (CVE-2026-13774 through CVE-2026-14427).
- Firefox 152.0.6 resolves at least 40 vulnerabilities, with CVE-2026-15718 flagged as critical.
- Google’s internal security program awarded roughly $90,000 in bug bounties for the disclosed issues.
- Adobe, mentioned in parallel reporting, released updates for 88 vulnerabilities, though none are directly tied to the browser patches.
Official Statements & Responses: Vendor Guidance and Government Findings
Mozilla advises users to apply the July 14 update immediately and notes that, while no confirmed in-the-wild attacks have been reported, threat actors routinely weaponize newly disclosed flaws. Google’s security blog echoes this urgency, urging automatic updates and recommending additional hardening measures for high-risk environments, such as disabling unnecessary plugins and enforcing strict content-security policies. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms that none of the patched CVEs appear in its Known Exploited Vulnerabilities (KEV) catalog as of July 2026, indicating no verified active exploitation at the time of reporting.
Criticism & Opposition: Expert Warnings About Delayed Patching
Security analysts caution that the presence of public exploit code for CVE-2026-15718 and the historical speed with which attackers weaponize use-after-free bugs make postponing updates a high-risk decision. The consensus among experts is that the window between public disclosure and potential exploitation can be measured in days, underscoring the need for rapid deployment.
Conflicting Reports & Gaps: Exploit Code Availability vs. Lack of Confirmed Attacks
Sources differ on the exploitation status: Firefox’s advisory acknowledges publicly available exploit code for the WebAssembly bug, yet both vendors and CISA report no evidence of active, real-world exploitation. This discrepancy highlights a monitoring gap; while no attacks have been confirmed, the existence of functional exploit code suggests a latent threat that could materialize without timely patching.
Verbatim Quotes
- “Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page,” — NIST National Vulnerability Database description
- “Public exploit code already exists for some of these flaws, and a browser is exposed to the web constantly, so putting off updates is a bad bet.” — Security commentary, Softonic
- “The vulnerabilities span use-after-free, sandbox escape, privilege escalation, JIT miscompilation, information disclosure, and memory safety flaws.” — Rescana advisory conclusion
- “APT Groups using this vulnerability There is currently no public attribution of these vulnerabilities to any specific Advanced Persistent Threat (APT) groups.” — Rescana advisory, introduction
- “Both Google and Mozilla strongly recommend immediate updates, as browser vulnerabilities are often rapidly weaponized following public disclosure.” — Rescana advisory, conclusion
