chrome

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

An autonomous AI agent from security startup depthfirst discovered 21 zero-day vulnerabilities in FFmpeg, some latent for over two decades, highlighting AI's growing role in vulnerability detection. Meanwhile, Google released Chrome 149, patching a record 429 security bugs—including critical use-after-free flaws—with much of the increased workload attributed to managing a surge in AI-generated bug reports. These developments underscore the accelerating pace and volume of vulnerability discovery driven by AI, emphasizing the need for faster patch cycles and robust update mechanisms.

https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html

These Convincing Copyright Notices Are Designed to Steal Google Logins

A new phishing scam targets Chrome extension developers with fake copyright removal notices designed to steal Google login credentials. The scam uses publicly available extension information to create convincing personalized warnings and a fake Google sign-in window, pressuring victims to enter their credentials before a fabricated deadline. Developers are advised to verify warnings only through their Chrome Web Store dashboard and to safeguard accounts with strong authentication and security software.

https://www.malwarebytes.com/blog/threat-intel/2026/06/these-convincing-copyright-notices-are-designed-to-steal-google-logins

Google Chrome 148 Released with Fix for 127 Security Vulnerabilities – Update Now!

Google has released Chrome 148, a major update addressing 127 security vulnerabilities, including three critical flaws such as an integer overflow in the Blink engine and use-after-free bugs in Mobile and Chromoting components. Users across Windows, Mac, and Linux are urged to update immediately to protect against potential exploits, with significant bug bounties awarded to researchers who reported these issues.

https://cybersecuritynews.com/chrome148-vulnerabilities-patched/

Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks

Google has released a critical update for Chrome version 147.0.7727.137/138 that fixes 30 security vulnerabilities, including four severe use-after-free flaws enabling remote code execution attacks. Users and enterprises are strongly urged to update their browsers immediately to protect against remote attacks that could bypass Chrome’s sandbox and compromise systems without additional user interaction.

https://cybersecuritynews.com/chrome-vulnerabilities-2/

Cultivating a Robust and Efficient Quantum-safe HTTPS

Google's Chrome team is rolling out a program to implement quantum-safe HTTPS certificates using Merkle Tree Certificates (MTCs), which increase efficiency and transparency without compromising security. MTCs replace traditional certificate chains, reducing bandwidth usage while adopting post-quantum cryptography. The rollout has three phases: testing MTCs with existing certificates, inviting log operators for public MTCs, and establishing a new root store for MTCs. This initiative aims to ensure a robust, efficient, and scalable approach to enhanced web security amid evolving quantum threats.

https://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html

Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History

Malicious Chrome extensions, including CL Suite, are stealing sensitive data from Meta Business Suite users. These extensions exfiltrate TOTP codes, Business Manager analytics, and contact lists to attackers' servers. Other threats include over 500,000 VKontakte account hijackings and 32 AI-themed extensions that siphon user credentials. These attacks emphasize the growing misuse of browser extensions for data theft, prompting recommendations for cautious installation practices and regular audits.

https://thehackernews.com/2026/02/malicious-chrome-extensions-caught.html

Google Chrome’s AI-powered Security Feature Rolls Out to Everyone

Google Chrome has launched an AI-enhanced security feature, updating its “Enhanced Protection” for real-time defense against harmful sites and downloads. This feature, part of Chrome's Safe Browsing, was in testing for three months and is now available on all platforms. Although it offers proactive protection, it sends browsing data to Google when enabled, which is off by default. Users can activate it through the settings on various devices.

https://www.bleepingcomputer.com/news/google/google-chromes-ai-powered-security-feature-rolls-out-to-everyone/

Scroll to Top