Chrome and Firefox Updates Patch Dozens of Vulnerabilities
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. Chrome and Firefox Updates Patch Dozens of Vulnerabilities
By Dillip Chowdary • Sep 02, 2026 • Source: SecurityWeek
What happened
2: ~100 words. 5 sections, each with 2 paragraphs of 80–160 words: Section 1: P1 (110 words) + P2 (110 words) = 220 words * Section 2: P1 (110 words) + P2 (1
Google and Mozilla on Tuesday announced patches for dozens of vulnerabilities across Chrome and Firefox, including critical- and high-severity flaws. A fresh Chrome 152 update has been rolled out with fixes for 26 bugs, two of which are critical-severity use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352).
How it works

The update also addresses nine high-severity security defects, including use-after-free, incorrect authorization, information leak, improper input validation, uninitialized resource, and buffer overflow weaknesses. Per Google’s advisory, only three of the flaws were reported by external researchers, but no bug bounty reward has been disclosed.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Why it matters
The latest Chrome iteration is now rolling out as versions 152.0.7977.75/.76 for Windows and macOS, and as version 152.0.7977.75 for Linux. See the full write-up from SecurityWeek via the source link for quotes and complete context.
Who is affected
Read the original coverage at SecurityWeek via the source link above for the complete details and primary quotes.
What to watch next
Cross-check release notes and official docs before changing production systems based on early reporting.
Developer Action Items
- ☐ Inventory whether Google / macOS / Linux runs in prod, CI, staging, or on laptops before you debate severity.
- ☐ Pull the vendor advisory for CVE-2026-84353, CVE-2026-84352 and patch from that page — not from a social recap.
- ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold
Read →
Elastic Stack 9.4.6 released
Read →
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards
Read →
Dropbox breach seemingly caused by egregious authentication failure [U]
Read →
Today's Tech Pulse briefing
Full briefing →
Advertisement