Firefox and Chrome Rush Out Patches for Dozens of Security Flaws
Mozilla fixed 58 vulnerabilities in Firefox 154, while Google addressed 15 in Chrome 151, including two critical bugs that could let attackers run malicious code on your device.

Key points
- Firefox 154, released Tuesday, patches 58 security flaws, 20 of them rated high-severity.
- Two critical-severity buffer overflow bugs (a type of flaw where attackers stuff too much data into a program's memory to hijack it) were fixed in Chrome 151.
- Mozilla also shipped Thunderbird 154 with fixes for 55 separate vulnerabilities on the same day.
- Google found 11 of Chrome's 15 flaws itself; four were reported by outside researchers.
- Windows and macOS users received Chrome 151 as versions 151.0.7922.169/.170; Linux as 151.0.7922.169.
What happened?
Both Google and Mozilla pushed security updates on Tuesday, closing dozens of holes in their browsers. Unpatched, some of these flaws could let an attacker take control of your computer simply by getting you to visit a malicious website.
Mozilla's Firefox 154 arrived with patches for 58 CVEs (Common Vulnerabilities and Exposures, the standard system for labelling publicly known security flaws). Twenty carry a high-severity rating, and roughly half are memory safety bugs that attackers can exploit to run their own code on your machine. The breakdown is notable: six use-after-free bugs (where the program keeps using memory it already discarded), six privilege escalation flaws, two information disclosure issues, a sandbox escape, and a site isolation problem were all resolved in one drop. Mozilla's advisory notes the update also covers multiple internally discovered bugs leading to memory corruption, collectively assigned three CVEs.
Mozilla also released Thunderbird 154, its email client, with fixes for 55 vulnerabilities. Extended support versions of both Firefox and Thunderbird received patches the same day. This is the fifth Firefox security story we've tracked in the past 90 days; our 29 July report on a one-click Firefox flaw shows how quickly these windows close once attackers know the details.
How serious are the Chrome flaws?
Two of Chrome's 15 patched bugs are rated critical, the most serious category. Both are buffer overflow vulnerabilities in WebGL and Dawn, the components that handle browser graphics. A critical buffer overflow could let an attacker run any code they choose on your device.
The other 13 Chrome flaws are rated high-severity, covering race conditions (where two processes collide in a way attackers can exploit), type confusion bugs (where the program misidentifies what kind of data it's handling), and several other classes. Google discovered 11 of the 15 flaws through internal security work; the company hasn't yet disclosed bounty amounts for the four externally reported issues. Chrome 151 has been updated twice already this cycle: we reported 370 flaws patched on 30 July and 41 more on 7 August. Tuesday's release, at 15 bugs, is smaller but includes two critical findings.
| Browser / App | New Version | Vulnerabilities Patched | Highest Severity |
|---|---|---|---|
| Firefox | 154 | 58 | Critical |
| Thunderbird | 154 | 55 | High |
| Chrome | 151 | 15 | Critical |
| Firefox ESR | 115.39 / 140.14 / 153.1 | Multiple | High |
| Thunderbird ESR | 140.14 / 153.1 | Multiple | High |
Should ordinary users do anything?
Yes: update now. Both browsers update automatically, but it's worth confirming. In Chrome, click the three-dot menu, choose Help, then "About Google Chrome". Firefox users can find the same check under Help, then "About Firefox". Either way it takes seconds. Thunderbird is identical: open Help and check for updates. The longer you wait after a public advisory, the narrower the gap between disclosure and exploitation gets.



