UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
Chrome zero-day CVE-2026-85046 is under active attack as the sixth actively exploited Chrome vulnerability of 2026. A type confusion flaw in Chrome's V8 JavaScript engine lets attackers run code ...
Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit.
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such ...
BlueMoon chains Chrome and Windows zero-days to escape the browser sandbox, elevate privileges, and deliver malware on ...
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge ...
Looks like Google is racing out another Chrome fix after finding a high-severity zero-day already being used in real attacks, so if you are still putting off that little update prompt, this is the one ...
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild.
Chrome 153 was released with patches for 230 vulnerabilities, including an exploited zero-day (CVE-2026-87491) in the V8 JavaScript engine.
Google has fixed 230 Chrome vulnerabilities, including an actively exploited V8 zero-day that can trigger heap corruption.
The update fixes a high-severity flaw in Chrome’s V8 engine, but Google has not revealed who is using it or whom they ...