Chrome and Firefox updated with critical security fixes: a Firefox bug has public exploit code

Google and Mozilla both shipped browser updates in July for Chrome 150 and Firefox 152, closing a set of serious security flaws.

Google Chrome Download

Since the late-June stable release of Google Chrome 150, Google says it has patched 433 vulnerabilities from the initial release, another 27 on July 8, including CVE-2026-15112 and CVE-2026-15129, and 15 more on July 15, including CVE-2026-15764 and CVE-2026-15765. Mozilla Firefox 152 came out on June 16 with fixes for 40 vulnerabilities. Then Firefox 152.0.6, released on July 14, patched CVE-2026-15718, a critical JavaScript WebAssembly bug with public exploit code available, although Mozilla says there are no confirmed in-the-wild attacks.

A lot of these issues come down to use-after-free bugs and other forms of memory corruption. Those can let attackers crash the browser, run code through a malicious site, ad, or phishing link, chain multiple bugs together to break out of the sandbox, and in business settings go after credentials, session tokens, or other sensitive data through rogue extensions.

If you use Chrome or Firefox all the time, don’t sit on this update. Public exploit code already exists for some of these flaws, and a browser is exposed to the web constantly, so putting off updates is a bad bet.

You can install the updates from Google Chrome’s Settings > About Chrome and Mozilla Firefox’s Menu > Settings > About Firefox, then apply any pending updates and relaunch the browser.

Mozilla Firefox Download

GigaWiper malware surfaces on Windows PCs: it can spy and wipe

Microsoft first spotted GigaWiper in October 2025. It’s a Windows malware strain that blends remote-access Trojan behavior with disk-wiping attacks.

Malwarebytes Anti-Malware Download

Binary Defense took a closer look in March 2026 and analyzed the same malware under the name BLUERABBIT. Its researchers say GigaWiper is modular and stitched together from at least three older malware families, with code tied to Crucio ransomware and FlockWiper, which leaves one infection able to do two jobs at once: watch what’s happening on a system, then wreck it.

Binary Defense says GigaWiper can overwrite an entire physical drive, run a multi-pass wipe on the Windows drive, or pretend to be ransomware by encrypting files with a key that’s never saved. That kind of misdirection showed up in attacks like NotPetya, where victims could be led to believe recovery was still on the table when it wasn’t.

If you’re responsible for protecting businesses, government bodies, or critical infrastructure, pay attention to this one. Binary Defense links GigaWiper to an Iran-linked actor also associated with BLUEWIPE and SEWERGOO, known for targeting organizations in Israel, and the all-in-one design gives attackers a way to hold back obvious warning signs until later in the intrusion.

The malware goes after Windows systems and falls into the same geopolitically charged wiper pattern seen in the 2026 Stryker attack, which reports say wiped more than 80,000 devices across 79 countries, and in the late-2025 DynoWiper attempt against Poland’s energy sector.