Urgent Security Updates Released for Chrome and Firefox: Users Urged to Update Immediately
January 8, 2025Another critical vulnerability, identified as CVE-2025-0291, could enable remote execution of malicious code or denial of service attacks, and was reported by a researcher who received a $55,000 reward.
Two critical vulnerabilities affecting both Firefox and Mozilla's Thunderbird email client, CVE-2025-0242 and CVE-2025-0247, could facilitate remote code execution due to memory safety issues.
The latest versions of Google Chrome are 131.0.6778.260 for Android, 131.0.6778.264 for Linux, and 131.0.6778.264/265 for macOS, while the Long-Term Support version stands at 130.0.6723.191.
Mozilla developers assessed the remaining eight vulnerabilities in Firefox as medium risk, which could lead to bypasses, address bar spoofing, elevation of privilege, crashes, and improper certificate validation.
Although neither company has reported any instances of these vulnerabilities being exploited in the wild, users are strongly urged to update their browsers promptly.
Users of Chrome are advised to update to version 131.0.6778.264/265 for Windows and Mac, and version 131.0.6778.264 for Linux, which addresses four identified security vulnerabilities.
Among these vulnerabilities is a critical flaw that could allow attackers to execute arbitrary code remotely, potentially compromising systems or leaking sensitive information.
Google and Mozilla have released critical updates for their web browsers, Chrome and Firefox, addressing several high-risk security vulnerabilities.
One notable issue in Chrome involves a Type Confusion in the V8 JavaScript engine, which has been classified as high risk.
In Firefox, version 134 addresses a high-severity flaw, CVE-2025-0244, which allows attackers to spoof the browser's address bar and redirect users to fraudulent URLs.
Firefox version 134 includes fixes for 11 security vulnerabilities, three of which are classified as high severity, and Mozilla has also released updates for the Extended Support Release (ESR) versions.
To update their browsers, users can navigate to 'Help' -> 'About...' in the settings menu for Chrome and Firefox, while Android users can update Firefox through the Play Store.
Summary based on 3 sources
Get a daily email with more Tech stories
Sources
ZDNET • Jan 8, 2025
Update Chrome and Firefox now to patch these critical security flawsSecurityWeek • Jan 8, 2025
Chrome 131, Firefox 134 Updates Patch High-Severity Vulnerabilities