Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chrome 137, Firefox 139 Patch High-Severity Vulnerabilities

Posted on May 28, 2025May 28, 2025 By CWS

Google and Mozilla on Tuesday introduced the discharge of Chrome 137 and Firefox 139, with patches for a complete of 21 vulnerabilities between the 2 browsers, together with three rated excessive severity.

Chrome 137 brings 11 safety fixes, eight of which cowl safety defects reported by exterior researchers.

Of the eight externally reported bugs, two are high-severity reminiscence issues of safety, particularly a use-after-free defect in Compositing (CVE-2025-5063) and an out-of-bounds write flaw within the V8 JavaScript engine (CVE-2025-5280).

Whereas Google didn’t present technical particulars on the vulnerabilities, the exploitation of reminiscence security bugs may permit attackers to execute arbitrary code or crash the appliance. Mixed with flaws within the underlying system or a privileged course of, use-after-free points in Chrome can result in sandbox escape.

The newest Chrome replace additionally resolves 5 medium-severity safety defects within the Background Fetch API, FileSystemAccess API, Messages, BFCache, and libvpx, and one low-severity flaw in Tab Strip.

Google says it handed out $7,500 in bug bounty rewards to the reporting researchers, however it has but to find out the quantities to be paid for the high-severity vulnerabilities and two medium-severity bugs, so the ultimate quantity may very well be a lot increased.

The newest Chrome iteration is now rolling out as variations 137.0.7151.55/56 for Home windows and macOS and as model 137.0.7151.55 for Linux.

Firefox 139 was launched with patches for 10 vulnerabilities, together with a high-severity double-free challenge in libvpx (with no CVE identifier assigned) that would have led to reminiscence corruption and a doubtlessly exploitable crash.Commercial. Scroll to proceed studying.

Moreover, the browser replace resolves six medium-severity bugs resulting in cross-origin leak assaults, native code execution, cross-site leaks (XS-Leaks), and reminiscence corruption (that would have been exploited for arbitrary code execution).

On Tuesday, Mozilla additionally delivered Firefox ESR 128.11 with patches for eight of those vulnerabilities, and Firefox ESR 115.24 with fixes for 4 of them. Thunderbird 139 was rolled out with fixes for all 10 safety defects, whereas Thunderbird 128.11 got here out with patches for eight of the failings.

Whereas Google and Mozilla make no point out of any of those vulnerabilities being exploited within the wild, customers are suggested to replace their browsers as quickly as potential, as it’s not unusual for risk actors to focus on Chrome and Firefox bugs.

Associated: Chrome 136 Replace Patches Vulnerability With ‘Exploit within the Wild’

Associated: Chrome 136, Firefox 138 Patch Excessive-Severity Vulnerabilities

Associated: Chrome 135, Firefox 137 Updates Patch Extreme Vulnerabilities

Security Week News Tags:Chrome, Firefox, HighSeverity, Patch, Vulnerabilities

Post navigation

Previous Post: A 24-Hour Timeline of a Modern Stealer Campaign
Next Post: OneDrive Gives Web Apps Full Read Access to All Files

Related Posts

Chrome 138 Update Patches Zero-Day Vulnerability Security Week News
Microsoft Sinkholes Domains, Disrupts Notorious ‘Lumma Stealer’ Malware Operation Security Week News
ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact  Security Week News
Data Breach at Debt Settlement Firm Impacts 160,000 People Security Week News
Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Security Week News
Australian Human Rights Commission Discloses Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • How to Remove Your Data From Data Broker Sites
  • TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands
  • SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups
  • Critical Mitel Flaw Lets Hackers Bypass Login, Gain Full Access to MiVoice MX-ONE Systems
  • Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • How to Remove Your Data From Data Broker Sites
  • TP-Link Network Video Recorder Vulnerability Let Attackers Execute Arbitrary Commands
  • SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups
  • Critical Mitel Flaw Lets Hackers Bypass Login, Gain Full Access to MiVoice MX-ONE Systems
  • Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter Environments

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News