Security News

Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials
2025-06-05 15:53

Cybersecurity researchers have flagged several popular Google Chrome extensions that have been found to transmit data in HTTP and hard-code secrets in their code, exposing users to privacy and...

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2025-5419)
2025-06-04 11:16

Google has fixed two Chrome vulnerabilities, including a zero-day flaw (CVE-2025-5419) with an in-the-wild exploit. About CVE-2025-5419 CVE-2025-5419 is a high-severity out of bounds read and...

Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild
2025-06-03 19:23

TAG team spotted the V8 bug first, so you can bet nation-states weren’t far behind Google revealed Monday that it had quietly deployed a configuration change last week to block active exploitation...

Google patches new Chrome zero-day bug exploited in attacks
2025-06-03 10:22

Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year. [...]

Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues
2025-06-03 07:48

Google has revealed that it will no longer trust digital certificates issued by Chunghwa Telecom and Netlock citing "patterns of concerning behavior observed over the past year." The changes are...

New Chrome Zero-Day Actively Exploited; Google Issues Emergency Out-of-Band Patch
2025-06-03 04:22

Google on Monday released out-of-band fixes to address three security issues in its Chrome browser, including one that it said has come under active exploitation in the wild. The high-severity...

Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August
2025-06-02 17:36

Google says it will no longer trust root CA certificates signed by Chunghwa Telecom and Netlock in the Chrome Root Store due to a pattern of compliance failures and failure to make improvements. [...]

New EDDIESTEALER Malware Bypasses Chrome's App-Bound Encryption to Steal Browser Data
2025-05-30 14:14

A new malware campaign is distributing a novel Rust-based information stealer dubbed EDDIESTEALER using the popular ClickFix social engineering tactic initiated via fake CAPTCHA verification...

Data-stealing Chrome extensions impersonate Fortinet, YouTube, VPNs
2025-05-21 15:13

A Google Chrome Web Store campaign uses over 100 malicious browser extensions that mimic legitimate tools, such as VPNs, AI assistants, and crypto utilities, to steal browser cookies and execute...

Google Chrome's Built-in Manager Lets Users Update Breached Passwords with One Click
2025-05-21 07:11

Google has announced a new feature in its Chrome browser that lets its built-in Password Manager automatically change a user's password when it detects the credentials to be compromised. "When...