Chrome 152 and Firefox 155 Fix Dozens of Security Flaws

Google and Mozilla released Chrome 152 and Firefox 155 updates. They fix critical and high-severity flaws, including issues involving memory safety, the sandbox and permissions.

Chrome 152 and Firefox 155 bring security fixes for two widely used web browsers. Google and Mozilla released the updates on September 1, 2026; Chrome fixes 26 vulnerabilities, while Firefox 155 lists 29 CVEs. In their respective advisories, the vendors do not state that any of the fixed flaws were exploited in real-world attacks.

Chrome 152 and Firefox 155: Critical and High-Severity Flaws

Google released Chrome 152.0.7977.75/.76 for Windows and macOS, while the Linux version is designated 152.0.7977.75. The update is being rolled out gradually, so it may not be immediately available on all devices.

Chrome includes 26 security fixes in total. These include two critical use-after-free flaws, which involve the program handling memory that has already been released. CVE-2026-84353 affects the Shared Tab Groups component, while CVE-2026-84352 affects WebGL.

Mozilla also published an advisory for Firefox 155 listing 29 CVE identifiers. They include flaws rated high severity, including use-after-free, sandbox escape and privilege escalation issues. The exact practical impact of each flaw depends on the affected component, platform and attack conditions. The severity rating alone therefore does not automatically mean that each flaw enables remote code execution.

Supported Firefox ESR Branches Also Receive Fixes

Mozilla also released updates for Firefox ESR branches, which are commonly used by organizations with managed devices. Firefox ESR 115.40, 140.15 and 153.2 are available. These releases cover some of the same vulnerabilities as the newer Firefox 155.

Administrators should therefore check not only the regular Firefox version but also the deployed ESR branches. For Chrome, it is advisable to check whether the relevant update version has already been installed on desktop devices, as distribution is gradual.

Why Browser Updates Matter

Web browsers regularly process content from untrusted sources. Flaws in memory management, sandbox isolation or permissions are therefore particularly significant in targeted-attack scenarios. The released fixes are currently the known mitigation for the vulnerabilities listed above.

Public exploitation of the flaws fixed in these releases has not been confirmed. Neither Google nor Mozilla mentions it in their cited security advisories. More information may become available after Chrome 152 distribution is complete or additional technical details about its vulnerability records are released.

  • Chrome for Windows and macOS: 152.0.7977.75/.76
  • Chrome for Linux: 152.0.7977.75
  • Firefox: 155
  • Firefox ESR: 115.40, 140.15 and 153.2

Sources

Verified and updated: 09/02/2026 13:13

Sharing