The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.

Recent updates for Google Chrome and Mozilla Firefox have addressed numerous security vulnerabilities, according to reports. The patches collectively resolve dozens of flaws, including critical issues such as use-after-free errors, sandbox escapes, and privilege escalation bugs, enhancing the overall security posture of both widely used web browsers.
Among the patched vulnerabilities, use-after-free errors are a common class of memory corruption bug. These occur when a program attempts to use memory after it has been freed, often leading to crashes, arbitrary code execution, or other unpredictable behavior. In the context of a web browser, successful exploitation of such a flaw could allow an attacker to run malicious code on a user's system, potentially compromising their data or system integrity.
Sandbox escape vulnerabilities are particularly concerning as browsers typically employ sandboxing mechanisms to isolate web content and restrict its access to the underlying operating system. An attacker who successfully exploits a sandbox escape can bypass these security boundaries, gaining greater control over the user's system than intended. This could facilitate further compromise, such as installing malware or accessing sensitive files.
Privilege escalation bugs, also addressed in these updates, allow an attacker to gain higher levels of access or permissions than they legitimately possess. For example, an attacker might escalate from a low-privilege user to an administrator, enabling them to make significant changes to the system or access restricted resources. In a browser context, this could mean elevating the privileges of malicious code running within the browser to impact the operating system directly.
Users are strongly advised to update their Chrome and Firefox browsers immediately to the latest versions. Browser updates typically include these critical security fixes, and delaying updates leaves systems vulnerable to known exploits. Most modern browsers are configured to update automatically, but users should verify their browser's update status or manually initiate an update if necessary to ensure they are protected against these newly patched vulnerabilities.
These updates underscore the continuous effort required to maintain browser security against a constantly evolving threat landscape. Web browsers are frequently targeted due to their pervasive use and their role as a primary interface to the internet, making them a critical vector for attacks. Regular patching cycles are a standard industry practice for software vendors to address newly discovered vulnerabilities and protect their user base from potential exploitation.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.