Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome 137, Firefox 139 Patch High-Severity Vulnerabilities

Chrome 137, Firefox 139 Patch High-Severity Vulnerabilities

Posted on May 28, 2025May 28, 2025 By CWS

Google and Mozilla on Tuesday introduced the discharge of Chrome 137 and Firefox 139, with patches for a complete of 21 vulnerabilities between the 2 browsers, together with three rated excessive severity.

Chrome 137 brings 11 safety fixes, eight of which cowl safety defects reported by exterior researchers.

Of the eight externally reported bugs, two are high-severity reminiscence issues of safety, particularly a use-after-free defect in Compositing (CVE-2025-5063) and an out-of-bounds write flaw within the V8 JavaScript engine (CVE-2025-5280).

Whereas Google didn’t present technical particulars on the vulnerabilities, the exploitation of reminiscence security bugs may permit attackers to execute arbitrary code or crash the appliance. Mixed with flaws within the underlying system or a privileged course of, use-after-free points in Chrome can result in sandbox escape.

The newest Chrome replace additionally resolves 5 medium-severity safety defects within the Background Fetch API, FileSystemAccess API, Messages, BFCache, and libvpx, and one low-severity flaw in Tab Strip.

Google says it handed out $7,500 in bug bounty rewards to the reporting researchers, however it has but to find out the quantities to be paid for the high-severity vulnerabilities and two medium-severity bugs, so the ultimate quantity may very well be a lot increased.

The newest Chrome iteration is now rolling out as variations 137.0.7151.55/56 for Home windows and macOS and as model 137.0.7151.55 for Linux.

Firefox 139 was launched with patches for 10 vulnerabilities, together with a high-severity double-free challenge in libvpx (with no CVE identifier assigned) that would have led to reminiscence corruption and a doubtlessly exploitable crash.Commercial. Scroll to proceed studying.

Moreover, the browser replace resolves six medium-severity bugs resulting in cross-origin leak assaults, native code execution, cross-site leaks (XS-Leaks), and reminiscence corruption (that would have been exploited for arbitrary code execution).

On Tuesday, Mozilla additionally delivered Firefox ESR 128.11 with patches for eight of those vulnerabilities, and Firefox ESR 115.24 with fixes for 4 of them. Thunderbird 139 was rolled out with fixes for all 10 safety defects, whereas Thunderbird 128.11 got here out with patches for eight of the failings.

Whereas Google and Mozilla make no point out of any of those vulnerabilities being exploited within the wild, customers are suggested to replace their browsers as quickly as potential, as it’s not unusual for risk actors to focus on Chrome and Firefox bugs.

Associated: Chrome 136 Replace Patches Vulnerability With ‘Exploit within the Wild’

Associated: Chrome 136, Firefox 138 Patch Excessive-Severity Vulnerabilities

Associated: Chrome 135, Firefox 137 Updates Patch Extreme Vulnerabilities

Security Week News Tags:Chrome, Firefox, HighSeverity, Patch, Vulnerabilities

Post navigation

Previous Post: A 24-Hour Timeline of a Modern Stealer Campaign
Next Post: OneDrive Gives Web Apps Full Read Access to All Files

Related Posts

Dragos Launches EmberAI for Enhanced OT Cybersecurity Dragos Launches EmberAI for Enhanced OT Cybersecurity Security Week News
Eurail Breach Affects 300,000 Customers’ Data Eurail Breach Affects 300,000 Customers’ Data Security Week News
CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary Security Week News
Why We Can’t Let AI Take the Wheel of Cyber Defense Why We Can’t Let AI Take the Wheel of Cyber Defense Security Week News
Malware Distributed via Cloned AI Tool Sites in New Campaign Malware Distributed via Cloned AI Tool Sites in New Campaign Security Week News
Sophisticated Koske Linux Malware Developed With AI Aid Sophisticated Koske Linux Malware Developed With AI Aid Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark