Google and Mozilla released major browser security updates to address more than 70 vulnerabilities across Chrome and Firefox, many tied to memory-safety weaknesses that could lead to remote code execution, sandbox escape, or privilege escalation. Chrome 149.0.7827.155/.156 fixes 33 flaws, including seven critical issues and 26 high-severity bugs; six of the critical flaws were reported as use-after-free vulnerabilities. Mozilla issued Firefox 152 along with Firefox ESR 115.37 and 140.12, remediating 40 vulnerabilities affecting areas such as memory corruption, denial of service, spoofing, sensitive information disclosure, and security restriction bypass.
Mozilla highlighted CVE-2026-12304, a same-origin policy bypass in the Networking: Cookies component with a CVSS score of 9.1, and CVE-2026-12289, a privilege-escalation flaw in Graphics: WebRender rated 8.8. Firefox’s fixes also covered high-severity bugs involving use-after-free conditions, JIT miscompilation, boundary-condition errors, and sandbox escape. No confirmed in-the-wild exploitation was reported at publication, but organizations were urged to deploy the updates quickly, restart browsers, and enforce enterprise browser-update policies to reduce exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Google released Chrome 149.0.7827.155/.156 with fixes for 33 vulnerabilities, including seven critical flaws and 26 high-severity issues. The patched bugs included multiple memory safety problems such as use-after-free vulnerabilities that could enable remote code execution or sandbox escape.
On 2026-06-17, Mozilla released Firefox 152 and Firefox ESR 115.37 and 140.12 to fix multiple security vulnerabilities. The updates addressed issues including denial-of-service, spoofing, privilege escalation, memory corruption, information disclosure, security restriction bypass, and arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourceegfincirt.org.eg
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.