Chrome and Firefox fix 108 flaws on the same day

Published

Google and Mozilla shipped browser security updates on the same day, 29 September, and between them the two releases fix 108 flaws. Chrome 154.0.8037.92 carries 32 security fixes, one of them rated critical. Firefox 157 carries 76, with 38 rated high, the top rating Mozilla assigned this round.

Neither vendor says any of them is being exploited. That makes this a routine patch day, if a heavy one, and one name in the credits turns up on both sides.

One critical Chrome bug, in graphics again

Google describes the critical flaw, CVE-2026-102331, only as a buffer overflow in ANGLE, the layer that translates a web page's graphics calls for the machine's own driver. A researcher using the handle @mfx reported it on 24 August. Of the other 31 fixes, 25 are rated high, one medium and five low. The high-severity set includes six bugs in the V8 JavaScript engine (five type confusions and a buffer overflow), a run of uninitialized-resource issues in the GPU, WebGPU, Dawn, Skia and Media code, and use-after-free bugs in Bluetooth, Views, Passwords, FullScreen and PictureInPicture. As usual, Srinivas Sista's release post keeps bug details restricted until most users have updated, so a one-line description is all anyone outside Google has.

ANGLE also produced three of the eleven criticals in last week's Chrome 154 release.

Firefox now counts its memory bugs one by one

Mozilla's Firefox 157 advisory lists 76 identifiers: 38 high, 29 moderate and nine low. Fifteen are described as sandbox escapes, bugs that could let code break out of the restricted process a web page runs in. Mozilla's own staff found most of the batch, and outside reporters include Yaqoub Aldurayhim, 5up3rh3i, Finn Westendorf, Rintaro Kawasugi and Tencent KeenLab's CodeBuddy Security team.

The advisory also carries a note on method. Mozilla says it no longer rolls internally identified memory-safety bugs into a single catch-all CVE and now issues one per bug. That helps explain the size of the list, and it means a raw count is a poor way to compare this release with Mozilla's September round or anything earlier.

OpenAI shows up in both credit lists

Google credits "OpenAI Codex Security (amyb)" with three of Chrome's high-severity V8 type confusions: CVE-2026-102323, CVE-2026-102326 and CVE-2026-102328. Mozilla credits Amy Burnett of OpenAI with two high-impact JIT miscompilations, one in the WebAssembly component (CVE-2026-100792) and one in the JavaScript engine (CVE-2026-100793). Neither vendor says how the bugs were found, and neither credit line says more than a name.

Update to Chrome 154.0.8037.92 and Firefox 157

The fixed Chrome builds are 154.0.8037.92 on Linux and 154.0.8037.92 or .93 on Windows and Mac. For Mozilla, update to Firefox 157, Firefox ESR 153.4, ESR 140.17 or ESR 115.42. Google rolls its release out over days to weeks, and both browsers only apply a downloaded update after a restart, so check the About page rather than assume. Managed fleets on an extended support branch should note the three ESR advisories carry different fix sets: 62 identifiers for ESR 153.4, 43 for ESR 140.17 and 31 for ESR 115.42. Chromium-based browsers such as Edge, Brave and Opera take Google's fixes on their own schedules.

Hong Kong's HKCERT relayed both releases on 30 September, rating each medium risk, in its Chrome bulletin and Firefox bulletin. No known exploitation and 108 fixes is the good version of patch day. The restart is what keeps it that way.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions