Vulnerability
Published 2026-09-15
Verified 2026-09-19

Chrome 153.0.8010.47/.48 (42 fixes) and Firefox 156 (MFSA 2026-90); no in-wild claim

Google Stable Channel Update for Desktop (15 September 2026) promotes Chrome to 153.0.8010.47/.48 (Windows/Mac) and 153.0.8010.47 (Linux) with 42 security fixes. Critical entries include CVE-2026-91726 (OOB read in WebGL), CVE-2026-91721 (UAF in Internals), and CVE-2026-91749 (UAF in Workers), plus numerous High UAFs, race conditions, and related issues. Distinct from desk card cve-2026-87491 (Chrome 153.0.8010.36/.37 V8 OOB-write 0-day on 8 Sep). Mozilla MFSA 2026-90 (announced 15 September 2026) ships Firefox 156 with individual CVEs for high-impact bugs (privilege escalation / UAF / WebGL boundary issues among others; Thunderbird 156 / ESR trains also updated per SecurityWeek). Neither vendor claims exploitation in the wild for this batch. SecurityWeek (16 Sep) summarised ~115 combined defects. Primary: Chrome Releases + Mozilla MFSA 2026-90.

Product
Google Chrome; Mozilla Firefox (and related Thunderbird/ESR builds per MFSA family)
Versions
Chrome prior to 153.0.8010.47/.48 (Win/Mac) / 153.0.8010.47 (Linux); Firefox prior to 156
Exploited in Australia?
unknown
Patch to
Update Chrome to 153.0.8010.47/.48 (or newer); update Firefox to 156 (and Thunderbird/ESR builds listed in related MFSAs)

Primary: Chrome Releases — Stable desktop 153.0.8010.47/.48 (15 Sep 2026) · Vendor: Mozilla MFSA 2026-90 — Firefox 156 (15 Sep 2026) · CVE: CVE-2026-91726, CVE-2026-91721, CVE-2026-91749, CVE-2026-87491 · SecurityWeek — Chrome/Firefox 115 vulns (16 Sep 2026)

vulnerabilities network