Chrome 152.0.7977.75/.76 and Firefox 155: critical UAF and high-severity browser fixes
Google's Stable Channel Update for Desktop (2 September 2026) promotes Chrome to 152.0.7977.75/.76 on Windows and Mac and 152.0.7977.75 on Linux with 26 security fixes. Critical: CVE-2026-84353 use-after-free in Shared Tab Groups and CVE-2026-84352 use-after-free in WebGL (both Google-reported). Nine High issues include FileSystem incorrect authorization (CVE-2026-84354), Skia information leak (CVE-2026-84359), Omnibox input validation (CVE-2026-84357), and several use-after-free / buffer issues in Proxy, Browser, Dawn, GPU and V8. Distinct from desk card cve-2026-79290 (earlier Chrome 152.0.7977.64/.65 Critical Aura/ANGLE set, 25 Aug). SecurityWeek says Mozilla shipped Firefox 155 the same day with patches for 29 defects including 13 high-severity use-after-free, sandbox escape, and memory-corruption issues. Update Chrome and Firefox promptly; this desk does not invent CVSS for Google's Critical labels.
- Product
- Google Chrome; Mozilla Firefox
- Versions
- Chrome fixed in 152.0.7977.75/.76 (Win/Mac) and 152.0.7977.75 (Linux); Firefox 155 per SecurityWeek
- Exploited in Australia?
- unknown
- Patch to
- Chrome 152.0.7977.75/.76 (or later); Firefox 155 or later
Primary: Chrome Stable Channel Update for Desktop (2 Sep 2026) · Vendor: Google Chrome Releases · CVE: CVE-2026-84353, CVE-2026-84352, CVE-2026-84354, CVE-2026-84359, CVE-2026-84357, CVE-2026-79290 · SecurityWeek (2 Sep 2026; Chrome + Firefox 155)
