Tag: browser
-
Ein falscher Klick reicht: Schadcode-Attacken auf Chrome-Nutzer beobachtet
Google hat Patches für hochgefährliche Chrome-Lücken veröffentlicht. Eine davon wird bereits aktiv ausgenutzt. Anwender sollten zügig updaten. First seen on golem.de Jump to article: www.golem.de/news/ein-falscher-klick-reicht-schadcode-attacken-auf-chrome-nutzer-beobachtet-2609-212654.html
-
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome’s JavaScript and WebAssembly engine.”Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a…
-
Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released
Google has released an urgent update for Chrome Stable to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively being exploited. This flaw can allow remote attackers to execute code within Chrome’s sandbox by convincing a victim to open a specially crafted HTML page. The security update…
-
Mozilla rolls out ad blocking to Firefox for iOS
Tags: browserFirst seen on scworld.com Jump to article: www.scworld.com/brief/mozilla-rolls-out-ad-blocking-to-firefox-for-ios
-
Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers
Mozilla has introduced a built-in ad blocker for Firefox on iOS, providing iPhone users with a native option to block many third-party advertisements and advertising-related trackers before they load in the browser. Announced on September 1, 2026, this feature aims to reduce intrusive browsing elements such as pop-ups, overlays, and display advertisements that take up…
-
Verbesserte Tab-Organisation – Firefox 155 unterstützt Nintendo Switch Pro Controller
Firefox 155 bringt unter anderem Unterstützung für Nintendo Switch Pro Controller und kompatible Controller bei Spielen im Web. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/verbesserte-tab-organisation-firefox-155-unterstuetzt-nintendo-switch-pro-controller.99191
-
Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled…
-
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential…
-
Chrome und Edge: Mehrere Browser-Add-ons per Update mit Malware verseucht
Forscher haben 19 mit Malware verseuchte Browsererweiterungen für Chrome und Edge entdeckt. Der Schadcode wurde erst nachträglich eingeschleust. First seen on golem.de Jump to article: www.golem.de/news/chrome-und-edge-mehrere-browser-add-ons-per-update-mit-malware-verseucht-2608-212452.html
-
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active…
-
Update Chrome before you browse again
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/update-chrome-before-you-browse-again/
-
Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This stable-channel update is being rolled out as version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS. This update is significant due to the sheer number and severity of memory-safety issues fixed across Chrome’s…
-
Jetzt updaten: Hunderte Sicherheitslücken in Google Chrome gepatcht
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden. First seen on golem.de Jump to article: www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-chrome-gepatcht-2608-212303.html
-
Jetzt updaten: 327 Sicherheitslücken in Google Chrome gepatcht
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden. First seen on golem.de Jump to article: www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-chrome-gepatcht-2608-212303.html
-
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there’s a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There’s a chance that you have just handed a complete stranger access to your savings. First seen on bitdefender.com Jump to article:…
-
Google Tests Built-In Opt-Out in Chrome for Data Sharing and Sales
Google is testing Global Privacy Control in Chrome Canary, letting users ask websites not to sell or share their data or use it for targeted advertising online. First seen on hackread.com Jump to article: hackread.com/google-tests-opt-out-chrome-data-sharing-sales/
-
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with several high-severity issues affecting various components of the browser, including V8, DOM, Workers, networking, and Linux toolkit theming. The update is being rolled out as version 151.0.7922.173/.174 for…
-
Network of 77 Firefox extensions linked to crypto theft uncovered
First seen on scworld.com Jump to article: www.scworld.com/brief/network-of-77-firefox-extensions-linked-to-crypto-theft-uncovered
-
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed…
-
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted
A broad Firefox add-on campaign that includes 13 malicious Rabby Wallet impersonators engineered to exfiltrate wallet keyring data before the application encrypts it locally. The activity is part of a larger operation, provisionally tracked as “Offside Wallet Theft Factory,” which links 77 Firefox extension identities through cloned code, reused infrastructure, deceptive listings, stable add-on IDs,…
-
Update Chrome now: Two critical vulnerabilities fixed
Google has released a Chrome desktop update fixing 15 security vulnerabilities, including 2 buffer overflow flaws rated critical. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/update-chrome-now-two-critical-vulnerabilities-fixed/
-
Thunderbird 154 – Update bringt Microsoft Graph und neue Mac-Vorschau
Neben Firefox hat Mozilla nun auch Thunderbird in Version 154 veröffentlicht, zum Update gehören zahlreiche Verbesserungen und Korrekturen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/thunderbird-154-update-bringt-microsoft-graph-und-neue-mac-vorschau.98914
-
Browser Firefox 154 will Schutz im lokalen Netzwerk erhöhen
Firefox führt mit Version 154 zahlreiche neue Funktionen ein, die vor allem die Sicherheit erhöhen sollen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/browser-update-firefox-154-will-schutz-im-lokalen-netzwerk-erhoehen.98899
-
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
-
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company’s own private code repositories.That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not…
-
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey was unintentionally committed to a private GitHub repository. The affected signing infrastructure includes selected release files, such as Linux tarballs, RPM packages, and checksum files. Mozilla’s investigation into available audit logs…
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication. The Stable channel update began rolling out on August 6 and will reach users over the next several…
-
Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts
Security researchers have demonstrated an indirect prompt-injection chain affecting Claude in Chrome that can transform a standard request, such as summarizing recent emails, into a cross-account takeover scenario. The research reveals how untrusted content viewed by an AI browser agent can exploit authenticated browser sessions to steal email-delivered verification secrets and compromise accounts on services…
-
Zenity Labs Finds Zero-Click Attack Chains Across Agentic Browsers
Zenity Labs released research at Black Hat USA 2026 showing zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge. The attacks demonstrated paths to silent data theft, credential theft, account takeover and remote control of a victim’s machine. PleaseFix abuses the way agentic browsers combine information..…

