Tag: chrome
-
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
A lot of this week’s trouble starts with something that looks close enough.A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation.Old bugs are back, weak defaults are earning their keep, and some attack paths…
-
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar.Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt…
-
ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History Theft
ModHeader version 7.0.187.0.187.0.18, a popular Chrome extension used for modifying HTTP headers, contained dormant code capable of collecting and exfiltrating browsing history data from an estimated 900,000 users, according to research disclosed on July 13, 2026. Google removed the extension from the Chrome Web Store on Friday, July 10, following a responsible disclosure. Organizations should…
-
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version.The collector was dormant. An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a single…
-
Google Chrome Update Patches 27 Security Vulnerabilities Including Critical UseFree Flaws
Google has released a critical security update for Chrome, upgrading the Stable channel to version 150.0.7871.114/.115 on Windows and macOS, and to version 150.0.7871.114 on Linux. This update addresses 27 vulnerabilities, including several critical use-after-free flaws that could potentially enable remote code execution. The update will roll out gradually over the coming days and weeks,…
-
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider.”The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise…
-
Gefälschte Perplexity-Erweiterung spioniert Suchanfragen aus
Eine gefälschte Chrome-Erweiterung für Perplexity AI hat Suchanfragen abgefangen und Nutzerdaten gesammelt. Google hat das Add-on inzwischen entfernt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/chrome-gefaelscht-perplexity
-
Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions
A widescale escalation in the PolinRider supply”‘chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm, Packagist, Go modules, and a Chrome extension, linking this activity to the broader North Korean Contagious Interview…
-
New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile
Google released a Chrome update addressing 382 security bugs, including sandbox-escape risks. Users and IT teams should update quickly. The post New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-update-382-security-bugs/
-
Google loses final appeal to overturn Euro4.1 billion EU fine
Court of Justice of the European Union (CJEU) has dismissed Google’s final appeal against a Euro4.1 billion ($4.7 billion) antitrust fine over the company’s use of Android to promote its Chrome browser and search service. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/legal/google-loses-final-appeal-to-overturn-41-billion-eu-fine/
-
Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features
Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now. The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-fake-perplexity-chrome-extension-searches/
-
Fake “Google Notes” Browser Extension Caught Swapping Crypto Wallet Addresses
McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users. First seen on hackread.com Jump to article: hackread.com/fake-google-notes-browser-extension-swap-crypto-wallets/
-
Riesiges Update: 382 Sicherheitslücken in Google Chrome entdeckt
Die neueste Chrome-Version schließt fast 400 teils kritische Sicherheitslücken. Auch für Edge, Vivaldi und Brave dürften entsprechende Updates folgen. First seen on golem.de Jump to article: www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-chrome-entdeckt-2607-210372.html
-
Riesiges Update: 382 Sicherheitslücken in Google Chrome entdeckt
Die neueste Chrome-Version schließt fast 400 teils kritische Sicherheitslücken. Auch für Edge, Vivaldi und Brave dürften entsprechende Updates folgen. First seen on golem.de Jump to article: www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-chrome-entdeckt-2607-210372.html
-
Google Chrome 151 Released With 382 Security Fixes for Critical Vulnerabilities
Google has promoted Chrome 151 to the stable channel for Windows, macOS and Linux, delivering a major security update that addresses 382 vulnerabilities across the browser’s core engine, graphics stack, extensions framework and cross”‘platform components. The release, dated June 30, 2026, significantly hardens Chrome against memory corruption, type confusion, and policy”‘enforcement flaws that could be…
-
Silent Swap Uses Fake Chrome Extension to Steal Crypto
Silent Swap uses a fake Chrome extension to silently replace cryptocurrency wallet addresses and steal digital assets. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/silent-swap-uses-fake-chrome-extension-to-steal-crypto/
-
Fake Perplexity extension on Chrome Web Store tracked searches
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-perplexity-extension-on-chrome-web-store-tracked-searches/
-
Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs
Google’s Chrome 149 security update fixes 18 bugs, including four critical flaws affecting WebGL, Autofill, and Blink components. The post Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-chrome-149-security-update/
-
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.Microsoft says Google removed it from the store after responsible disclosure. The…
-
Rokarolla Uses Fake Google Play Protect App to Target Banking and Cryptocurrency Users
Rokarolla, a sophisticated Android banking trojan distributed via malicious websites that masquerade as trusted applications such as TikTok, Google Chrome and even Google Play Protect. Unlike simple credential stealers, Rokarolla is a multi-functional fraud platform that targets at least 217 banking and cryptocurrency apps and combines Accessibility Service abuse, phishing overlays, SMS interception, keylogging, screenshot…
-
Millionen YouTube-Adblocker enthalten inaktiven Schadcode
Eine Chrome-Erweiterung mit über zehn Millionen Downloads kann laut Forschern unbemerkt schadhaften JavaScript-Code auf beliebigen Webseiten ausführen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/youtube-adblocker-schadcode
-
Chrome-Erweiterung: Mögliche Backdoor in millionenfach installiertem Adblocker
Mit mehr als zehn Millionen Installationen ist Adblock for Youtube eine der beliebtesten Chrome-Erweiterungen. Doch sie birgt erhebliche Gefahren. First seen on golem.de Jump to article: www.golem.de/news/chrome-erweiterung-moegliche-backdoor-in-beliebtem-youtube-adblocker-entdeckt-2606-210227.html
-
Chrome-Erweiterung: Backdoor in millionenfach installiertem Adblocker entdeckt
Mit mehr als zehn Millionen Installationen ist Adblock for Youtube eine der beliebtesten Chrome-Erweiterungen. Doch sie birgt erhebliche Gefahren. First seen on golem.de Jump to article: www.golem.de/news/chrome-erweiterung-moegliche-backdoor-in-beliebtem-youtube-adblocker-entdeckt-2606-210227.html
-
Chrome-Erweiterung: Mögliche Backdoor in beliebtem Youtube-Adblocker entdeckt
Mit mehr als zehn Millionen Installationen ist Adblock for Youtube eine der beliebtesten Chrome-Erweiterungen. Doch sie birgt erhebliche Gefahren. First seen on golem.de Jump to article: www.golem.de/news/chrome-erweiterung-moegliche-backdoor-in-beliebtem-youtube-adblocker-entdeckt-2606-210227.html
-
Google Chrome Update Patches 18 Security Flaws, Including Critical WebGL and Autofill Vulnerabilities
Google has released Chrome version 149.0.7827.196/197 for Windows and macOS, and version 149.0.7827.196 for Linux. This update addresses 18 security vulnerabilities, including several critical memory safety flaws in the WebGL and Autofill components. The announcement was made on June 23, 2026, and the update is being rolled out gradually over the coming days and weeks.…
-
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code.According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million installs and carries a Featured badge on the Chrome Web Store.The extension description states that it allows users to…
-
Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords
JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route. First seen on hackread.com Jump to article: hackread.com/fake-npm-packages-postcss-tool-steal-chrome-password/
-
Payouts King Initial Access Broker Deploys Edgecution Malware Through Malicious Edge Extension
A concerted campaign by an initial access broker with ties to the Payouts King ransomware ecosystem that leverages a novel browser-based delivery technique to establish persistent host-level control. The actor deploys a malicious Microsoft Edge extension dubbed >>Edgecution<< which abuses the Chrome native messaging protocol to reach a Python backdoor running on the endpoint, effectively…
-
Vidar Infostealer Bypasses Google Chrome’s ABE Encryption via APC Injection
A sophisticated evasion technique developed by Vidar infostealer operators successfully bypasses Google Chrome’s Application-Bound Encryption (ABE). Introduced in 2024, ABE was designed to protect browser-stored cookies and sensitive credentials. According to recent findings by Gen Threat Labs, the latest iterations of Vidar are now dropping weekly updates that utilize a complex chain of process forking,…
-
Vidar Infostealer Bypasses Google Chrome’s ABE Encryption via APC Injection
A sophisticated evasion technique developed by Vidar infostealer operators successfully bypasses Google Chrome’s Application-Bound Encryption (ABE). Introduced in 2024, ABE was designed to protect browser-stored cookies and sensitive credentials. According to recent findings by Gen Threat Labs, the latest iterations of Vidar are now dropping weekly updates that utilize a complex chain of process forking,…

