Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chrome 137, Firefox 139 Patch High-Severity Vulnerabilities

Posted on May 28, 2025May 28, 2025 By CWS

Google and Mozilla on Tuesday introduced the discharge of Chrome 137 and Firefox 139, with patches for a complete of 21 vulnerabilities between the 2 browsers, together with three rated excessive severity.

Chrome 137 brings 11 safety fixes, eight of which cowl safety defects reported by exterior researchers.

Of the eight externally reported bugs, two are high-severity reminiscence issues of safety, particularly a use-after-free defect in Compositing (CVE-2025-5063) and an out-of-bounds write flaw within the V8 JavaScript engine (CVE-2025-5280).

Whereas Google didn’t present technical particulars on the vulnerabilities, the exploitation of reminiscence security bugs may permit attackers to execute arbitrary code or crash the appliance. Mixed with flaws within the underlying system or a privileged course of, use-after-free points in Chrome can result in sandbox escape.

The newest Chrome replace additionally resolves 5 medium-severity safety defects within the Background Fetch API, FileSystemAccess API, Messages, BFCache, and libvpx, and one low-severity flaw in Tab Strip.

Google says it handed out $7,500 in bug bounty rewards to the reporting researchers, however it has but to find out the quantities to be paid for the high-severity vulnerabilities and two medium-severity bugs, so the ultimate quantity may very well be a lot increased.

The newest Chrome iteration is now rolling out as variations 137.0.7151.55/56 for Home windows and macOS and as model 137.0.7151.55 for Linux.

Firefox 139 was launched with patches for 10 vulnerabilities, together with a high-severity double-free challenge in libvpx (with no CVE identifier assigned) that would have led to reminiscence corruption and a doubtlessly exploitable crash.Commercial. Scroll to proceed studying.

Moreover, the browser replace resolves six medium-severity bugs resulting in cross-origin leak assaults, native code execution, cross-site leaks (XS-Leaks), and reminiscence corruption (that would have been exploited for arbitrary code execution).

On Tuesday, Mozilla additionally delivered Firefox ESR 128.11 with patches for eight of those vulnerabilities, and Firefox ESR 115.24 with fixes for 4 of them. Thunderbird 139 was rolled out with fixes for all 10 safety defects, whereas Thunderbird 128.11 got here out with patches for eight of the failings.

Whereas Google and Mozilla make no point out of any of those vulnerabilities being exploited within the wild, customers are suggested to replace their browsers as quickly as potential, as it’s not unusual for risk actors to focus on Chrome and Firefox bugs.

Associated: Chrome 136 Replace Patches Vulnerability With ‘Exploit within the Wild’

Associated: Chrome 136, Firefox 138 Patch Excessive-Severity Vulnerabilities

Associated: Chrome 135, Firefox 137 Updates Patch Extreme Vulnerabilities

Security Week News Tags:Chrome, Firefox, HighSeverity, Patch, Vulnerabilities

Post navigation

Previous Post: A 24-Hour Timeline of a Modern Stealer Campaign
Next Post: OneDrive Gives Web Apps Full Read Access to All Files

Related Posts

Google Warns UK Retailer Hackers Now Targeting US Security Week News
GRC Firm Vanta Raises $150 Million at $4.15 Billion Valuation Security Week News
Aflac Finds Suspicious Activity on US Network That May Impact Social Security Numbers, Other Data Security Week News
Four Arrested in UK Over M&S, Co-op Cyberattacks Security Week News
Dell Says Data Leaked by Hackers Is Fake Security Week News
Patrick Ware Named Executive Director of US Cyber Command Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • How to Report a Stolen Identity
  • Web-to-App Funnels: Pros And Cons
  • Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide
  • 10 Best API Monitoring Tools in 2025
  • U.S. Sanctions Firm Behind N. Korean IT Scheme; Arizona Woman Jailed for Running Laptop Farm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • How to Report a Stolen Identity
  • Web-to-App Funnels: Pros And Cons
  • Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide
  • 10 Best API Monitoring Tools in 2025
  • U.S. Sanctions Firm Behind N. Korean IT Scheme; Arizona Woman Jailed for Running Laptop Farm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News