Tag

Chrome

All articles tagged with #chrome

Researcher Demonstrates How Malicious Extensions Can Hijack Browser AI Agents
technology12 days ago

Researcher Demonstrates How Malicious Extensions Can Hijack Browser AI Agents

Security researcher Gal Weizman of Forever Security revealed a new attack vector called 'BragJack' that allows malicious browser extensions to hijack AI assistants in Chrome, Edge, and other Chromium-based browsers. By exploiting the declarativeNetRequest system, attackers can force AI agents to perform actions without additional user clicks, potentially accessing local files, screenshots, and camera feeds. The research led to over $20,000 in bug bounties and two CVEs, with Google and Microsoft confirming patches for the identified vulnerabilities.

Chrome patches in-the-wild V8 zero-day as part of 230 fixes
security1 month ago

Chrome patches in-the-wild V8 zero-day as part of 230 fixes

Google pushed Chrome updates to fix 230 vulnerabilities, including CVE-2026-87491 — an out-of-bounds write in V8 that has been exploited in the wild to run arbitrary code in the sandbox. The patch, for Windows/macOS versions 153.0.8010.36/37 and Linux 153.0.8010.36, also addresses multiple WebGL and WebPackaging flaws and follows seven actively exploited Chrome zero-days reported this year. Users of Chrome and other Chromium-based browsers should update promptly, noting that some bug details may remain restricted until most users are patched. OpenAI Codex Security is credited for a separate high-severity finding in WebPackaging.

Chrome Zero-Day Exploited in the Wild Gets Quick Patch (CVE-2026-87491)
technology1 month ago

Chrome Zero-Day Exploited in the Wild Gets Quick Patch (CVE-2026-87491)

Google issued patches for a new actively exploited Chrome zero-day in the V8 engine (CVE-2026-87491), rolling updates to Windows, macOS, and Linux; exploitation could allow remote code execution via crafted HTML and heap corruption, with Google restricting full exploit details until most users are updated. This marks the seventh Chrome zero-day addressed in 2026, following several earlier flaws.

Chrome patched after active zero-day exploit hits V8 engine
technology1 month ago

Chrome patched after active zero-day exploit hits V8 engine

Google released Chrome updates to fix a high‑severity zero‑day in the V8 engine (CVE-2026-85046) that is already being exploited in the wild, along with nine other high‑severity flaws. The patches cover Chrome on Windows/macOS (versions 152.0.7977.82/.83) and Linux (152.0.7977.82); users should install the update via Settings > About Chrome and restart the browser. The fixes also apply to Chromium‑based browsers like Edge, Brave, Opera, and Vivaldi as updates roll out.

Chrome Patch Fends Off Actively Exploited V8 Zero-Day
security1 month ago

Chrome Patch Fends Off Actively Exploited V8 Zero-Day

Google released a Chrome security update that patches 12 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-85046) that enables remote code execution via a crafted HTML page. An exploit already exists in the wild, and Google urges users to update to Chrome 152.0.7977.82/83 on Windows and macOS, and 152.0.7977.82 on Linux; the update also fixes five other CVEs (CVE-2026-2441, -3909, -3910, -5281, -11645), bringing the total of actively exploited Chrome zero-days addressed this year to six.

Gemini 3.5 Transcribe Accelerates AI Speech-to-Text Across Google Apps
technology1 month ago

Gemini 3.5 Transcribe Accelerates AI Speech-to-Text Across Google Apps

Google unveils Gemini 3.5 Transcribe, a faster (about 70% quicker) and more accurate AI voice-to-text model that cleans up disfluencies like ums and uhs, supports custom vocabulary, and works in 85 languages for up to three speakers. Initially live in Gboard’s Rambler on Pixel 11, it will expand to more Gemini devices and the Chrome browser soon, with macOS voice input benefiting today. Developers can access the Gemini API, and Google is integrating the tech with partners like Antigravity and AI Studio.

Microsoft Rolls Out Standalone Tool to Force Bing Across Windows 11 Browsers
technology1 month ago

Microsoft Rolls Out Standalone Tool to Force Bing Across Windows 11 Browsers

Microsoft released a standalone tool called MicrosoftSettings.exe (Microsoft Recommended Search Settings) that prompts users to set Bing as the default search across Edge, Chrome, and Firefox and then installs a Chrome extension to enforce Bing, followed by a redirect to the Microsoft Rewards page after setup; the app isn’t distributed via Windows Update or the Microsoft Store and uses a WinUI shell with WebView2 to push the extension. Chrome and Brave warn about the extension, and prompts to revert can appear, illustrating Microsoft’s ongoing effort to push Bing across browsers—even allowing sign-in to Bing with Google or Apple accounts.

Chrome slashes Android notification abuse with multi-layer defense, saving billions daily
technology1 month ago

Chrome slashes Android notification abuse with multi-layer defense, saving billions daily

Google says Chrome’s anti-abuse measures reduced unwanted Android notifications by more than 7 billion per day in Q1 2026, using a layered “Swiss cheese” defense that automatically revokes permissions from inactive or suspicious sites, throttles excessive prompts, and reshapes notification prompts to be less disruptive, while giving users ongoing control via Safety Hub and Android’s settings.

Claude in Chrome Expands to a Cross-Device Cowork Session
technology1 month ago

Claude in Chrome Expands to a Cross-Device Cowork Session

Anthropic's Claude for Chrome now supports a full Cowork session, letting browser-based tasks and conversations persist across Claude's desktop, web, and mobile apps. Sessions are saved to Claude history, with existing skills and connectors usable in the browser; available for Max and Team now, with a Pro rollout planned. Admins can enable and restrict access to approved domains, while safeguards acknowledge browser agent risks such as prompt injection.

Chrome adds hardware-backed session keys to curb account takeovers
technology2 months ago

Chrome adds hardware-backed session keys to curb account takeovers

Google Chrome is adding device-bound session credentials (DBSCs) that store a private key in hardware (TPM on Windows, Secure Enclave on macOS/iOS) to sign authentication challenges, making stolen session cookies useless for account takeover. Currently limited to a test rollout on Windows and macOS, the feature aims to reduce reliance on shared secrets and work alongside passkeys and 2FA; other Chromium-based browsers may adopt it as the standard progresses via the W3C.

Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID
security2 months ago

Fresh Passkey Flaws Threaten MFA Across Windows, Chrome, and Entra ID

Three independent groups revealed passkey-related attack vectors that don’t break cryptography: exploiting exposed Windows-stored signed data to impersonate privileged users via Entra ID, compromising Google Password Manager’s synced passkeys in Chrome to recover private keys, and abusing a compromised Windows session to use a Windows Hello for Business key for new WebAuthn assertions. Impacts vary, with mitigations including CVE-2026-34348 fixes, enforcing user-verification for WebAuthn, and strengthened endpoint/zero-trust protections; no single fix exists since issues lie in surrounding controls, not math.

Four Trade-Offs to Consider When Ditching Chrome for Firefox
technology2 months ago

Four Trade-Offs to Consider When Ditching Chrome for Firefox

Firefox offers stronger privacy protections and lighter memory use, but switching from Chrome comes with four drawbacks: a far smaller extension ecosystem (about 69k extensions in Firefox vs ~289k in Chrome), potential site and app compatibility issues due to Firefox's different web tech support, slower performance in benchmarks compared with Chrome, and weaker, less seamless integration with Google services (no built‑in password management or account-wide syncing).

Chrome to block policy-installed hijacker extensions on unmanaged devices
technology2 months ago

Chrome to block policy-installed hijacker extensions on unmanaged devices

Google is adding a Chrome defense that blocks policy-controlled extensions from overriding the New Tab page or default search on unmanaged Windows and macOS devices. When detected, the installation is canceled and the extension ID is blocked for future policy checks; manual extensions remain controllable and a device that loses trusted management will have affected extensions automatically removed. The change is still under review and not yet shipped, but would be enabled by default via the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices flag, with metrics and an escape hatch for legitimate admins.

Stretch Your MacBook Pro Battery Life With Simple Tweaks
technology2 months ago

Stretch Your MacBook Pro Battery Life With Simple Tweaks

Practical steps to extend MacBook Pro battery life: monitor energy use to spot demanding apps (Chrome often drains power due to tab processes), consider Safari for better efficiency (Edge is a middle-ground option), keep macOS updated for bug fixes and improvements, enable Low Power Mode, and adjust hardware settings (lower brightness, disable ProMotion by using 60Hz, and let the display sleep on battery). Also ensure the device sits on a stable surface for cooling and manage keyboard backlight as needed for longer sessions.