Google and Mozilla released security updates for Chrome, Firefox, and Firefox ESR to fix multiple high-severity and critical browser vulnerabilities. Reporting on the latest releases says Chrome addressed 27 flaws, including critical use-after-free bugs CVE-2026-15112 in Ozone and CVE-2026-15129 in the Views UI framework, both of which could allow arbitrary code execution through a crafted webpage. Separate Chrome advisories and follow-on reporting also highlighted another recent batch of fixes covering 18 security holes, underscoring a sustained stream of browser patching activity.
Mozilla's updates fixed two critical vulnerabilities, CVE-2026-49825 and CVE-2026-49826, affecting the JavaScript engine and browser engine in Firefox and Firefox ESR. One report said public exploit code is available for both flaws, increasing the urgency for defenders to deploy updates quickly. Across the referenced advisories, the common risk is browser compromise through memory-corruption and related bugs that can lead to credential theft, session hijacking, malware delivery, and broader enterprise access if users remain on unpatched versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Google and Mozilla released browser security updates addressing multiple high-severity and critical vulnerabilities in Chrome, Firefox, and Firefox ESR. The report says Chrome fixed 27 vulnerabilities including critical flaws CVE-2026-15112 and CVE-2026-15129, while Mozilla fixed critical flaws CVE-2026-49825 and CVE-2026-49826, with public exploit code available for both Mozilla issues.
A July 2026 report states that Chrome had 18 security holes addressed by an update, highlighting a vulnerability-fixing browser patch event. The source does not explicitly anchor the underlying release to a specific event date beyond the article's publication context.
Mozilla released a Firefox security update on 2026-07-06, as reflected in the referenced advisory notice. This represents a distinct patch event for Firefox.
Google issued a Chrome security update on 2026-07-05, marking another browser patch release in the sequence of referenced updates.
A separate Google Chrome security update was published on 2026-06-25, indicating an additional patch event distinct from the prior day's release.
Google released Chrome security updates on 2026-06-24, according to the referenced security update notice. The content indicates a distinct Chrome patch event occurred on that date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcemeetcyber.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcemozilla.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.