
Four software products used by hundreds of millions of people worldwide have released critical security updates this week, and security researchers are urging users to install them immediately. Mozilla fixed two critical flaws in Firefox that already have working exploit code published publicly — meaning attackers can use those blueprints to attack unpatched browsers. Google shipped fixes for 15 Chrome vulnerabilities, including two critical bugs that could let a remote attacker corrupt your browser’s memory by tricking you into certain mouse gestures. Adobe patched 88 vulnerabilities across products like Illustrator and ColdFusion, and Broadcom fixed a critical authentication-bypass flaw (CVSS score 9.8) in VMware’s Avi Load Balancer.
The urgency here is real: when exploit code is already publicly available, attackers don’t need to invest time figuring things out on their own. Keeping your browser and software even a few days out of date during a window like this meaningfully raises your risk. The good news is that all four fixes are free and easy to apply — it’s just a matter of doing it today rather than later.
How to check if you’re affected
Affected versions of Firefox are anything older than 152.0.6. To check, open Firefox, click the three-line menu in the top right, choose Help → About Firefox — it will display your version and update automatically if needed.
For Chrome, affected versions are older than 150.0.7871.124 (Windows/Mac) or 150.0.7871.124 (Linux). Go to the three-dot menu → Help → About Google Chrome to check and trigger an update.
For Adobe products, affected versions of ColdFusion are those prior to ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22 — most home users can safely ignore the Adobe patches unless you or someone in your home runs a web server with ColdFusion. VMware Avi Load Balancer is an enterprise product; if your company uses it, alert your IT department to apply the Broadcom fix immediately.
