Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chrome 137, Firefox 139 Patch High-Severity Vulnerabilities

Posted on May 28, 2025May 28, 2025 By CWS

Google and Mozilla on Tuesday introduced the discharge of Chrome 137 and Firefox 139, with patches for a complete of 21 vulnerabilities between the 2 browsers, together with three rated excessive severity.

Chrome 137 brings 11 safety fixes, eight of which cowl safety defects reported by exterior researchers.

Of the eight externally reported bugs, two are high-severity reminiscence issues of safety, particularly a use-after-free defect in Compositing (CVE-2025-5063) and an out-of-bounds write flaw within the V8 JavaScript engine (CVE-2025-5280).

Whereas Google didn’t present technical particulars on the vulnerabilities, the exploitation of reminiscence security bugs may permit attackers to execute arbitrary code or crash the appliance. Mixed with flaws within the underlying system or a privileged course of, use-after-free points in Chrome can result in sandbox escape.

The newest Chrome replace additionally resolves 5 medium-severity safety defects within the Background Fetch API, FileSystemAccess API, Messages, BFCache, and libvpx, and one low-severity flaw in Tab Strip.

Google says it handed out $7,500 in bug bounty rewards to the reporting researchers, however it has but to find out the quantities to be paid for the high-severity vulnerabilities and two medium-severity bugs, so the ultimate quantity may very well be a lot increased.

The newest Chrome iteration is now rolling out as variations 137.0.7151.55/56 for Home windows and macOS and as model 137.0.7151.55 for Linux.

Firefox 139 was launched with patches for 10 vulnerabilities, together with a high-severity double-free challenge in libvpx (with no CVE identifier assigned) that would have led to reminiscence corruption and a doubtlessly exploitable crash.Commercial. Scroll to proceed studying.

Moreover, the browser replace resolves six medium-severity bugs resulting in cross-origin leak assaults, native code execution, cross-site leaks (XS-Leaks), and reminiscence corruption (that would have been exploited for arbitrary code execution).

On Tuesday, Mozilla additionally delivered Firefox ESR 128.11 with patches for eight of those vulnerabilities, and Firefox ESR 115.24 with fixes for 4 of them. Thunderbird 139 was rolled out with fixes for all 10 safety defects, whereas Thunderbird 128.11 got here out with patches for eight of the failings.

Whereas Google and Mozilla make no point out of any of those vulnerabilities being exploited within the wild, customers are suggested to replace their browsers as quickly as potential, as it’s not unusual for risk actors to focus on Chrome and Firefox bugs.

Associated: Chrome 136 Replace Patches Vulnerability With ‘Exploit within the Wild’

Associated: Chrome 136, Firefox 138 Patch Excessive-Severity Vulnerabilities

Associated: Chrome 135, Firefox 137 Updates Patch Extreme Vulnerabilities

Security Week News Tags:Chrome, Firefox, HighSeverity, Patch, Vulnerabilities

Post navigation

Previous Post: A 24-Hour Timeline of a Modern Stealer Campaign
Next Post: OneDrive Gives Web Apps Full Read Access to All Files

Related Posts

Gambling Tech Firm Bragg Discloses Cyberattack Security Week News
Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit Security Week News
European Airport Disruptions Caused by Ransomware Attack Security Week News
Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws Security Week News
Connex Credit Union Data Breach Impacts 172,000 People Security Week News
Google Warns of Vishing, Extortion Campaign Targeting Salesforce Customers Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary
  • Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information
  • The ‘Kitten’ Project – Hacktivist Groups Carrying Out Attacks Targeting Israel
  • Tri-Century Eye Care Data Breach Impacts 200,000 Individuals
  • USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary
  • Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information
  • The ‘Kitten’ Project – Hacktivist Groups Carrying Out Attacks Targeting Israel
  • Tri-Century Eye Care Data Breach Impacts 200,000 Individuals
  • USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark