Tag: chrome
-
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential…
-
Chrome und Edge: Mehrere Browser-Add-ons per Update mit Malware verseucht
Forscher haben 19 mit Malware verseuchte Browsererweiterungen für Chrome und Edge entdeckt. Der Schadcode wurde erst nachträglich eingeschleust. First seen on golem.de Jump to article: www.golem.de/news/chrome-und-edge-mehrere-browser-add-ons-per-update-mit-malware-verseucht-2608-212452.html
-
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active…
-
Update Chrome before you browse again
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/update-chrome-before-you-browse-again/
-
Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This stable-channel update is being rolled out as version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS. This update is significant due to the sheer number and severity of memory-safety issues fixed across Chrome’s…
-
Jetzt updaten: Hunderte Sicherheitslücken in Google Chrome gepatcht
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden. First seen on golem.de Jump to article: www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-chrome-gepatcht-2608-212303.html
-
Jetzt updaten: 327 Sicherheitslücken in Google Chrome gepatcht
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden. First seen on golem.de Jump to article: www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-chrome-gepatcht-2608-212303.html
-
Google Tests Built-In Opt-Out in Chrome for Data Sharing and Sales
Google is testing Global Privacy Control in Chrome Canary, letting users ask websites not to sell or share their data or use it for targeted advertising online. First seen on hackread.com Jump to article: hackread.com/google-tests-opt-out-chrome-data-sharing-sales/
-
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with several high-severity issues affecting various components of the browser, including V8, DOM, Workers, networking, and Linux toolkit theming. The update is being rolled out as version 151.0.7922.173/.174 for…
-
Update Chrome now: Two critical vulnerabilities fixed
Google has released a Chrome desktop update fixing 15 security vulnerabilities, including 2 buffer overflow flaws rated critical. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/update-chrome-now-two-critical-vulnerabilities-fixed/
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication. The Stable channel update began rolling out on August 6 and will reach users over the next several…
-
Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts
Security researchers have demonstrated an indirect prompt-injection chain affecting Claude in Chrome that can transform a standard request, such as summarizing recent emails, into a cross-account takeover scenario. The research reveals how untrusted content viewed by an AI browser agent can exploit authenticated browser sessions to steal email-delivered verification secrets and compromise accounts on services…
-
Zenity Labs Finds Zero-Click Attack Chains Across Agentic Browsers
Zenity Labs released research at Black Hat USA 2026 showing zero-click PleaseFix exploit chains across Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge. The attacks demonstrated paths to silent data theft, credential theft, account takeover and remote control of a victim’s machine. PleaseFix abuses the way agentic browsers combine information..…
-
Chrome to Block Policy-Abusing Extensions on Personal Devices
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices. The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-chrome-extension-policy-abuse/
-
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap. The post Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-twice-weekly-security-updates/
-
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen.Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets…
-
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, the actors behind the XCSSET malware resurfaced with version 40 (v40), a major re-architecture of the…
-
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team…
-
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of…
-
Google Uses AI to Fix 1,072 Chrome Security Vulnerabilities
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149 and 150. This number exceeds the total number of bugs patched across the previous 23 milestones combined. In a new report, the Chrome Security Team detailed how large language models are integrated throughout the vulnerability…
-
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
As experts have warned for the last two years, some companies, like Microsoft and now Google, are finding and patching an exponential number of bugs in their products, thanks to the use of LLMs and AI tools. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/
-
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser’s two most recent releases as it expands its use of AI. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/
-
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator mark a clear architectural evolution in the group’s malware-as-a-service (MaaS) ecosystem, signaling a shift…
-
Google Chrome 150 Update Fixes Four High-Severity Security Vulnerabilities
Google Chrome version 150.0.7871.186 has addressed four high-severity vulnerabilities that affect core browser components, including Codecs, WebMCP, Blink, and Input. While Google has not reported any evidence indicating that these vulnerabilities are actively being exploited, the company has restricted access to technical bug reports and related information until a majority of Chrome users receive the…
-
Chaos ransomware deploys browser-based msaRAT to evade network detection
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware…
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge…
-
Über Add-on von Adobe: Forscher zeigen Whatsapp-Datenklau mit nur einem Klick
Über 300 Millionen Nutzer vertrauen einer Chrome-Erweiterung von Adobe. Angreifer konnten darüber jedoch leicht Whatsapp-Chats ausleiten. First seen on golem.de Jump to article: www.golem.de/news/adobe-acrobat-populaeres-chrome-add-on-hat-whatsapp-datenklau-ermoeglicht-2607-211189.html

