Google and Mozilla both shipped browser updates in July for Chrome 150 and Firefox 152, closing a set of serious security flaws.
Since the late-June stable release of Google Chrome 150, Google says it has patched 433 vulnerabilities from the initial release, another 27 on July 8, including CVE-2026-15112 and CVE-2026-15129, and 15 more on July 15, including CVE-2026-15764 and CVE-2026-15765. Mozilla Firefox 152 came out on June 16 with fixes for 40 vulnerabilities. Then Firefox 152.0.6, released on July 14, patched CVE-2026-15718, a critical JavaScript WebAssembly bug with public exploit code available, although Mozilla says there are no confirmed in-the-wild attacks.
A lot of these issues come down to use-after-free bugs and other forms of memory corruption. Those can let attackers crash the browser, run code through a malicious site, ad, or phishing link, chain multiple bugs together to break out of the sandbox, and in business settings go after credentials, session tokens, or other sensitive data through rogue extensions.
If you use Chrome or Firefox all the time, don’t sit on this update. Public exploit code already exists for some of these flaws, and a browser is exposed to the web constantly, so putting off updates is a bad bet.
You can install the updates from Google Chrome’s Settings > About Chrome and Mozilla Firefox’s Menu > Settings > About Firefox, then apply any pending updates and relaunch the browser.