#browser-security
35 stories taggedbrowser-security · page 2 of 3.

Google Patches Seven Memory Safety Bugs in Chrome 150, Three Rated Critical
All seven flaws were found internally or by researchers, not by criminals. But history says patch fast anyway.

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers
The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

A Flaw in Claude's Chrome Extension Let Rogue Add-ons Hijack the AI Assistant
Anthropic patched a bug that let malicious browser extensions puppet Claude into touching a user's Gmail, Google Docs, and Salesforce accounts.

Firefox Rushes Out Fix After Attack Code for Two Critical Bugs Appears Online
Mozilla says working exploit code is already public for two serious flaws in its browser. Users should update now.

The AI Blind Spot in Corporate Security: Why Old Traffic Inspection Is Falling Behind
Employees are pasting company secrets into ChatGPT and installing rogue browser add-ons. The security tools most firms rely on can't see any of it.

Google Patches 27 Chrome Flaws, Two Rated Critical
Chrome 150 arrives with fixes for a string of memory-related bugs, most of them found by Google's own engineers rather than outside researchers.

Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On
Researchers rebuilt a signed-in user's Gmail address from one page visit. Opera has patched the flaw.

Google Patches Fifth Chrome Zero-Day of 2022 as Hackers Actively Exploit the Flaw
A flaw in how Chrome handles a mobile-linking feature is being weaponised in real attacks. It's the fifth time this year Google has had to rush out an emergency fix for its browser.

Opera's new Paste Protect tries to stop the copy-paste scam that's been draining wallets
The browser will now block dodgy commands before they reach your clipboard, targeting the ClickFix trick that has become criminals' favourite way to trick people into infecting their own computers.

Context Manipulation Attack 'BioShocking' Turns Agentic Browsers Into Credential Thieves
Researchers demonstrate how feeding poisoned context to AI-driven browser agents causes them to quietly drop safety guardrails and exfiltrate stored credentials.

DeepSeek-Generated PoC Ransomware Runs Entirely in the Browser via Chromium File System Access API
Researchers documented what they describe as the first frontier-model-produced malware artifact combining LLM ideation with a legitimate Chromium capability to encrypt user files without a native binary.

DeepSeek Spits Out Working Browser-Native Ransomware for Windows and Android
Researchers say a frontier model stitched together a real Chromium capability with fantasy malware ideas and produced something that actually encrypts files from inside a tab.

Malicious Extension Spoofs AI Platform to Intercept Searches
A fake browser extension impersonating Perplexity AI intercepted search queries, highlighting governance gaps in enterprise security.

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers
Researchers at LayerX got six AI browsers and assistants — including ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude extension — to exfiltrate user logins by framing the attack as a game.

Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke
Microsoft researchers flagged a counterfeit Perplexity Chrome extension that piped queries and omnibox input to an attacker server before completing the search.