Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Chrome and Firefox users must update ASAP

Mozilla released Firefox 135, which fixes two high-severity use-after-free bugs tracked as CVE-2025-1009 and CVE-2025-1010

byKerem Gülen
February 5, 2025
in Cybersecurity, News
Home News Cybersecurity

Google and Mozilla announced updates for their Chrome and Firefox browsers on Tuesday to address multiple high-severity memory safety vulnerabilities. Chrome 133 includes 12 security fixes, while Firefox 135 also resolves several critical issues.

Google and Mozilla release critical updates for Chrome and Firefox

Chrome 133, now available in versions 133.0.6943.53/54 for Windows and macOS, and 133.0.6943.53 for Linux, includes three notable vulnerabilities reported by external researchers. Two of these bugs are use-after-free defects tracked as CVE-2025-0444 and CVE-2025-0445, affecting the Skia graphics library and the V8 JavaScript engine, respectively. The third issue, CVE-2025-0451, is a medium-severity inappropriate implementation flaw in the Extensions API component.

Google reported that it awarded a $7,000 bug bounty for the vulnerability in Skia and a $2,000 reward for the medium-severity flaw. The bounty for the second high-severity vulnerability in V8 has yet to be determined. Use-after-free vulnerabilities may lead to code execution, data corruption, or denial of service, and in the context of Chrome, they could facilitate a sandbox escape if combined with a privileged bug.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.


Flexible-Ferret malware targets Mac users by doding XProtect measures


In a parallel update, Mozilla released Firefox 135, which fixes two high-severity use-after-free bugs tracked as CVE-2025-1009 and CVE-2025-1010, affecting the Custom Highlight API and Extensible Stylesheet Language Transformations (XSLT). The Firefox update also addresses CVE-2025-1016 and CVE-2025-1020, high-severity memory safety bugs impacting both Thunderbird and Firefox ESR, which could potentially lead to code execution.

Firefox 135 also resolves seven medium- and low-severity vulnerabilities that could allow spoofing attacks, code execution, use-after-free issues, privacy leaks, and improper certificate checks. Like Google, Mozilla did not disclose any incidents of these vulnerabilities being actively exploited, but users are strongly advised to update their browsers immediately.

For updates, users can navigate within Chrome by clicking the three-dot menu, selecting “Help,” and then “About Google Chrome” to automatically check for and install updates. The urgency for both Chrome and Firefox users to apply these updates stems from the potential for attackers to exploit these vulnerabilities for remote code execution and system control.


Featured image credit: Kerem Gülen/Ideogram

Tags: chromeCybersecurityfirefoxGooglemozilla

Related Posts

Zoom announces AI Companion 3.0 at Zoomtopia

Zoom announces AI Companion 3.0 at Zoomtopia

September 19, 2025
Google Cloud adds Lovable and Windsurf as AI coding customers

Google Cloud adds Lovable and Windsurf as AI coding customers

September 19, 2025
Radware tricks ChatGPT’s Deep Research into Gmail data leak

Radware tricks ChatGPT’s Deep Research into Gmail data leak

September 19, 2025
Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

September 19, 2025
Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

September 19, 2025
DeepSeek releases R1 model trained for 4,000 on 512 H800 GPUs

DeepSeek releases R1 model trained for $294,000 on 512 H800 GPUs

September 19, 2025

LATEST NEWS

Zoom announces AI Companion 3.0 at Zoomtopia

Google Cloud adds Lovable and Windsurf as AI coding customers

Radware tricks ChatGPT’s Deep Research into Gmail data leak

Elon Musk’s xAI chatbot Grok exposed hundreds of thousands of private user conversations

Roblox game Steal a Brainrot removes AI-generated character, sparking fan backlash and a debate over copyright

DeepSeek releases R1 model trained for $294,000 on 512 H800 GPUs

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.