Chrome

Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge

Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge 2026-05-01 at 18:20 By Eduard Kovacs The maximum reward for a zero-click Pixel Titan M exploit with persistence has increased to $1.5 million. The post Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge appeared first […]

Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge Read More »

To counter cookie theft, Chrome ships device-bound session credentials

To counter cookie theft, Chrome ships device-bound session credentials 2026-04-10 at 14:45 By Mirko Zorz Cookie theft follows a well-established pattern. Infostealer malware infiltrates a device, extracts authentication cookies, and exfiltrates them to an attacker-controlled server. Because cookies often have extended lifetimes, attackers can access accounts without passwords, then bundle and sell the stolen credentials.

To counter cookie theft, Chrome ships device-bound session credentials Read More »

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 2026-04-10 at 14:45 By Eduard Kovacs The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers. The post Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 appeared first on SecurityWeek. This article is an excerpt from

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 Read More »

Google Rolls Out Cookie Theft Protections in Chrome

Google Rolls Out Cookie Theft Protections in Chrome 2026-04-10 at 11:06 By Ionut Arghire New Device Bound Session Credentials render stolen session cookies unusable by cryptographically binding authentication. The post Google Rolls Out Cookie Theft Protections in Chrome appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Rolls Out Cookie Theft Protections in Chrome Read More »

Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome

Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome 2026-04-01 at 18:46 By Eduard Kovacs Google has announced fixes for CVE-2026-5281, a zero-day affecting Chrome’s Dawn component.  The post Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome Read More »

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281)

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281) 2026-04-01 at 14:31 By Zeljka Zorz Google has fixed 21 vulnerabilities affecting its popular Chrome browser, among them a zero-day (CVE-2026-5281) with an in-the-wild exploit. About CVE-2026-5281 As per usual, information about the fixed zero-day is limited, and there’s no details about the exploit (or how/if it’s

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281) Read More »

Chrome 146 Update Patches High-Severity Vulnerabilities

Chrome 146 Update Patches High-Severity Vulnerabilities 2026-03-24 at 19:53 By Ionut Arghire The software refresh fixes eight memory safety bugs affecting seven Chrome components. The post Chrome 146 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 146 Update Patches High-Severity Vulnerabilities Read More »

Chrome 146 Update Patches Two Exploited Zero-Days

Chrome 146 Update Patches Two Exploited Zero-Days 2026-03-13 at 09:50 By Ionut Arghire The flaws can be exploited to manipulate data and bypass security restrictions, potentially leading to code execution. The post Chrome 146 Update Patches Two Exploited Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 146 Update Patches Two Exploited Zero-Days Read More »

Google speeds up Chrome updates with new security-focused release cycle

Google speeds up Chrome updates with new security-focused release cycle 2026-03-04 at 16:08 By Sinisa Markovic The Chrome browser is moving to a two-week release cycle, a change intended to give developers and users faster access to new features, performance improvements and bug fixes. The new schedule begins with the stable release of Chrome 153

Google speeds up Chrome updates with new security-focused release cycle Read More »

Google Plans Two-Week Release Schedule for Chrome

Google Plans Two-Week Release Schedule for Chrome 2026-03-04 at 13:52 By Ionut Arghire Starting September 2026, new Chrome iterations will be released twice as fast, part of a two-week cycle. The post Google Plans Two-Week Release Schedule for Chrome appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Plans Two-Week Release Schedule for Chrome Read More »

Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant

Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant 2026-03-02 at 17:46 By Ionut Arghire Malicious extensions could hijack the Gemini Live in Chrome feature to spy on users and steal their files. The post Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant Read More »

Google Working Towards Quantum-Safe Chrome HTTPS Certificates 

Google Working Towards Quantum-Safe Chrome HTTPS Certificates  2026-03-02 at 13:47 By Ionut Arghire The internet giant is developing an evolution of the certificates based on Merkle Tree Certificates (MTCs). The post Google Working Towards Quantum-Safe Chrome HTTPS Certificates  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Working Towards Quantum-Safe Chrome HTTPS Certificates  Read More »

Grammarly and QuillBot are among widely used Chrome extensions facing serious privacy questions

Grammarly and QuillBot are among widely used Chrome extensions facing serious privacy questions 2026-01-28 at 08:15 By Anamarija Pogorelec A new study shows that some of the most widely used AI-powered browser extensions are a privacy risk. They collect lots of data and require a high level of browser access. The research was conducted by

Grammarly and QuillBot are among widely used Chrome extensions facing serious privacy questions Read More »

Chrome, Edge Extensions Caught Stealing ChatGPT Sessions

Chrome, Edge Extensions Caught Stealing ChatGPT Sessions 2026-01-27 at 15:49 By Ionut Arghire Marketed as ChatGPT enhancement and productivity tools, the extensions allow the threat actor to access the victim’s ChatGPT data. The post Chrome, Edge Extensions Caught Stealing ChatGPT Sessions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome, Edge Extensions Caught Stealing ChatGPT Sessions Read More »

Fake browser crash alerts turn Chrome extension into enterprise backdoor

Fake browser crash alerts turn Chrome extension into enterprise backdoor 2026-01-19 at 17:21 By Zeljka Zorz Browser extensions are a high-risk attack vector for enterprises, allowing threat actors to bypass traditional security controls and gain a foothold on corporate endpoints. Case in point: A recently identified malicious extension called NexShield proves that a single user

Fake browser crash alerts turn Chrome extension into enterprise backdoor Read More »

Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities

Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities 2026-01-14 at 11:50 By Ionut Arghire The two browser updates resolve 26 security defects, including bugs that could be exploited for code execution. The post Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities Read More »

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats 2026-01-07 at 17:35 By Ionut Arghire Impersonating a legitimate extension from AITOPIA, the two malicious extensions were also exfiltrating users’ browser activity. The post Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats Read More »

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw 2025-12-15 at 13:22 By Eduard Kovacs Apple has released macOS and iOS updates to patch two WebKit zero-days exploited in an “extremely sophisticated” attack. The post Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw appeared first on SecurityWeek. This article is an excerpt

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw Read More »

Google Patches Mysterious Chrome Zero-Day Exploited in the Wild

Google Patches Mysterious Chrome Zero-Day Exploited in the Wild 2025-12-11 at 09:49 By Eduard Kovacs The Chrome zero-day does not have a CVE and it’s unclear who reported it and which browser component it affects. The post Google Patches Mysterious Chrome Zero-Day Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt

Google Patches Mysterious Chrome Zero-Day Exploited in the Wild Read More »

Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks

Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks 2025-12-08 at 20:02 By Ionut Arghire Chrome’s new agentic browsing protections include user alignment critic, expanded origin-isolation capabilities, and user confirmations. The post Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks Read More »

Scroll to Top