< Back to all clusters
[TECHNOLOGY] · United States, Germany, United Kingdom · 2 sources

Browsers patch critical flaws; Google, Microsoft remove ModHeader

Within days, major technology firms issued emergency updates to close several high‑severity vulnerabilities. Google released a Chrome emergency update (version 150.0.7871.128) fixing three CVE‑2026‑15899/15900/15901 flaws rated 9.8, while Mozilla rolled out Firefox 152.0.6 to address two newly disclosed WASM/JavaScript bugs (CVE‑2026‑15718, CVE‑2026‑15719). 7‑Zip updated to version 26.02 to close a remote‑code‑execution flaw in XZ decompression, and additional deadlines from the U.S. Cybersecurity‑Infrastructure‑Security‑Agency forced patches for Oracle E‑Business‑Suite, SharePoint Server, and Fortinet FortiSandbox vulnerabilities.

Separately, Google and Microsoft removed the popular browser‑extension ModHeader from their stores after security firm Stripe OLT uncovered an inactive data‑collection module. The extension, installed around 1.6 million times, contained code to fingerprint devices, record up to 1,000 visited domains daily, encrypt the data, and queue it for upload to an external server—though the upload never occurred because the whitelist was empty. No evidence of actual data exfiltration has been found, but the removal prevents potential future spying.

Both incidents highlight a surge in critical software flaws and the swift remedial actions taken by vendors to protect millions of users and enterprises worldwide.