Update Chrome and Firefox now to patch these critical security flaws
January 9, 2025

Update Chrome and Firefox now to patch these critical security flaws

ZDNET

Whether you use Chrome, Firefox, or both, it’s time to update your browser again to stay safe while you surf the internet. Released on Tuesday, the latest round of bug fixes for both programs addresses a number of serious security flaws.

Also: The Best Secure Browsers for Privacy

Chrome users

Chrome users will want to update the browser to version 31.0.6778.264/265 for Windows and Mac and version 131.0.6778.264 for Linux. This update includes four security vulnerabilities fixed.

The only flaw on the list described by Google is one for which the company paid $55,000 to a security researcher who discovered and reported it, a sign that it is critical. Known as CVE-2025-0291this vulnerability refers to Type confusion in Chrome V8 JavaScript engine. Such a vulnerability could allow someone to remotely execute malicious code via a specially crafted HTML page or even launch a denial of service attack on your computer.

Also: How Fear of a Chrome Extension Ruined My Day

While addressing other bugs, Google pointed to fixes based on internal auditing, a software testing method known as fuzzingand other initiatives. The company said that many security flaws are detected using tools and techniques such as AddressSanitizer, Memory Sanitizer, UndefineBehaviorSanitizer, Control Flow Integrity, libFuzzeror AFL.

Firefox users

As for Firefox, version 134 of the Mozilla browser includes 11 security vulnerabilities fixedthree of which have a high rating, and the rest – average.

One serious drawback known as CVE-2025-0244 affects Firefox on Android devices. The description states that an attacker can spoof the browser’s address bar by redirecting the request to the wrong protocol, thereby directing you to a fake URL.

Also: How to protect yourself from phishing attacks in Chrome and Firefox

Two other serious vulnerabilities affect both Firefox and Mozilla’s Thunderbird email client. Dubbed CVE-2025-0242 And CVE-2025-0247accordingly, both of these were described by Google as memory safety errors indicating memory corruption. Such errors could allow a remote attacker to read or write code outside normal memory areas. “We suspect that with enough effort, some of these could be used to run arbitrary code,” Google added.

Given these critical security flaws, you need to update your browsers as soon as possible.

How to update your browser

To update Chrome on your desktop, click the three-dot icon at the top, go to Help, and select About Google Chrome. The browser will automatically install the latest update and then prompt you to restart it.

To update Firefox on your desktop, click the three-line hamburger icon at the top, select Help, and then click About Firefox. As with Chrome, Firefox will automatically run the latest update and then prompt you to restart it.

To update Firefox on your Android device, open the Play Store app, tap your profile icon in the top right corner, and then select the Manage apps & device setting. Allow your device to check for updates, and then click the Update All link to update all your apps.



2025-01-08 16:06:00

Leave a Reply

Your email address will not be published. Required fields are marked *