Tag: Google Chrome

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
News

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

According to Google, during the first quarter of 2026, Chrome's anti-abuse features decreased unsolicited notifications on Android by almost 7 billion per day. Google claims in a recent blog post that malware, phishing attempts, fraudulent payment requests, and scams are increasingly being distributed by notification abuse. Google created a "Swiss cheese" protection model to lessen exploitation, in which many overlapping systems attempt to prevent abuse at various stages. Google clarified, "Our goal is to make sure that if abuse slips thru one layer, another is there to catch it." By preventing misleading content from reaching consumers, this strategy enables us to stop misuse at its source while preserving a sound balance between read more about Google says Chrome cuts 7 billion...
Google Chrome may soon block New Tab hijacker extensions by default
News

Google Chrome may soon block New Tab hijacker extensions by default

Google is working on a new security feature for Chrome that would prevent policy-installed extensions from altering the default search engine or taking over the New Tab screen. The protection was discovered by BleepingComputer in a series of ongoing Chromium Gerrit modifications. Although it hasn't launched yet, Google intends to make it active by default after the modifications are accepted. According to a post by Google employee Anunoy Ghosh, enterprise policy force-installs and recommendations are misused to lock in search engine or new tab page hijackers in low-trust environments (unmanaged consumer devices). By default, this CL activates the end-to-end blocking defense on unmanaged Windows and macOS devices by turning on the kBlockDseNtpOverrideExtensionsOnUnmanagedDevices f...
Google Chrome adds infostealer protection against session cookie theft
News

Google Chrome adds infostealer protection against session cookie theft

In Chrome 146 for Windows, Google introduced Device Bound Session Credentials (DBSC) protection, which prevents malware that steals information from collecting session cookies. This security enhancement will be available to macOS users in an upcoming, unannounced Chrome edition. The new protection, which was unveiled in 2024, operates by cryptographically connecting a user's session to their particular hardware, like as the Secure Enclave on macOS and the Trusted Platform Module (TPM) on Windows. Sensitive data cannot be exported from the computer because the security chip generates the unique public/private keys needed to encrypt and decrypt it. Because the system cannot export the unique private key that protects the stolen session data, the attacker is prevented from exploi...
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor
News

Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor

A threat actor called TaxOff used a now-patched Google Chrome security hole as a zero-day attack to launch a backdoor nicknamed Trinper. Positive Technologies discovered the attack in mid-March 2025, and it used a sandbox escape vulnerability known as CVE-2025-2783 (CVSS score: 8.3). Later that month, after Kaspersky revealed in-the-wild exploitation in an operation called Operation ForumTroll that targeted multiple Russian groups, Google fixed the vulnerability. According to security specialists Vladislav Lunin and Stanislav Pyzhov, the first attack vector was a phishing email with a malicious link. The Trinper backdoor used by TaxOff was installed as a result of the user clicking the link, which set off a one-click exploit (CVE-2025-2783). According to Kaspersky, the phishing e...
New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy
News

New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

Google fixed four security flaws in its Chrome browser on Wednesday, including one for which it claimed there was an exploit in the wild. CVE-2025-4664, a high-severity vulnerability with a CVSS score of 4.3, has been described as an instance of inadequate policy enforcement in a component known as Loader. A summary of the vulnerability states that "a remote attacker was able to leak cross-origin data via a crafted HTML page due to inadequate policy enforcement in Loader in Google Chrome prior to 136.0.7103.113." The tech giant acknowledged that an attack for CVE-2025-4664 is in the wild and gave credit to security researcher Vsevolod Kokorin (@slonser_) for describing the X vulnerability on May 5, 2025. Chrome resolves the Link header on sub-resource requests, in contrast to ...
Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks
News

Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks

Google has addressed a high-severity security hole in its Chrome browser for Windows with out-of-band fixes, claiming that the flaw has been used in the wild as part of attacks against Russian organizations. The vulnerability has been identified as a case of "incorrect handle provided in unspecified circumstances in Mojo on Windows." It is listed as CVE-2025-2783. The term "Mojo" describes a group of runtime libraries that offer an inter-process communication (IPC) mechanism that is independent of platform. As is customary, Google did not disclose any more technical details regarding the type of assaults, the threat actors responsible, or the potential targets. The issue has been fixed in Chrome for Windows, version 134.0.6998.177/.178. Google said in a brief advisory that it is ...
New details reveal how hackers hijacked 35 Google Chrome extensions
News

New details reveal how hackers hijacked 35 Google Chrome extensions

New information has surfaced on a phishing campaign that targeted developers of Chrome browser extensions and compromised at least 35 extensions, including those from cybersecurity company Cyberhaven, to introduce code that stole data. Initial reports concentrated on Cyberhaven's security-focused extension, but further research showed that at least 35 extensions, used by almost 2,600,000 users, had the same code injected into them. According to targeted developers' complaints on Google Groups and LinkedIn, the most recent effort began around December 5, 2024. But as early as March 2024, BleepingComputer discovered previous command and control subdomains read more about New details reveal how hackers hijacked 35 Google Chrome extensions. Get up to date on the latest cybersecurity ...
Lazarus Group Exploits Google Chrome Vulnerability to Control Infected Devices
News

Lazarus Group Exploits Google Chrome Vulnerability to Control Infected Devices

The zero-day exploitation of a now-patched security hole in Google Chrome to take over infected machines has been linked to the North Korean threat actor Lazarus Group. According to cybersecurity provider Kaspersky, in May 2024, it uncovered a new attack chain that used the Manuscrypt backdoor to target the personal computer of an unidentified Russian resident. This involves launching the zero-day vulnerability just by going to a phony gaming website ("detankzone[.]com") that was targeted at bitcoin industry professionals. According to estimates, the campaign started in February 2024. According to Kaspersky researchers Boris Larin and Vasily Berdnikov read more about Lazarus Group Exploits Google Chrome Vulnerability to Control Infected Devices. Get up to date on the latest cy...
New ARM ‘TIKTAG’ attack impacts Google Chrome,Linux systems
News

New ARM ‘TIKTAG’ attack impacts Google Chrome,Linux systems

With almost a 95% likelihood of success, a novel speculative execution attack called "TIKTAG" targets ARM's Memory Tagging Extension (MTE) to leak data, enabling hackers to get around the security measure. The attack on Google Chrome and the Linux kernel is demonstrated in the paper, which is co-signed by a group of Korean academics from Samsung, Seoul National University, and the Georgia Institute of Technology. MTE is a feature intended to identify and stop memory corruption that was added to the ARM v8.5-A architecture (and later). By making sure that the tag in the pointer matches the accessible memory region, the system employs low-overhead tagging, which assigns 4-bit tags to 16-byte memory chunks, to defend against memory corruption attacks read more New ARM 'TIKTAG' attac...
Google Chrome Adds V8 Sandbox A New Defense Against Browser Attacks
News

Google Chrome Adds V8 Sandbox A New Defense Against Browser Attacks

To address memory corruption issues, Google has announced support for the so-called V8 Sandbox in the Chrome web browser. Samuel Groß, the technical lead for V8 Security, states that the sandbox is intended to stop "memory corruption in V8 from spreading within the host process." V8 Sandbox is a lightweight, in-process sandbox for the JavaScript and WebAssembly engine that is intended to minimize common V8 vulnerabilities, according to the search giant. By limiting the code executed by V8 to a portion of the process' virtual address space (referred to as "the sandbox") and isolating it from the remainder of the process, the impact of V8 vulnerabilities is intended to be mitigated read more Google Chrome Adds V8 Sandbox A New Defense Against Browser Attacks. Get up to date on t...