ZCyberNews
中文

#chrome

9 articles

The technology sector bore the brunt of Chrome-focused vulnerabilities between April and August 2026, with global implications for consumer, financial services, and government organizations. Across nine articles, six high-severity and three critical issues were documented. Key vulnerabilities included CVE-2026-8550 and CVE-2026-8556, both rated 6.5, alongside CVE-2026-8541 and CVE-2026-8543 at 5.3, and CVE-2026-8566 at 3. This archive tracks the evolving security landscape for the browser, highlighting the persistent need for vigilance across all sectors worldwide.

Diagram showing malware intercepting Chrome passkey authentication flow on WindowsHIGH
Malware

Pass-the-Passkey Attacks Hijack Chrome Synced Accounts

Unit 42 reveals Pass-ta-key attacks: malware on Windows Chrome endpoints steals synced passkeys, bypasses biometric verification, and extracts private keys without user...

3 min read
Screenshot of a browser-based ransomware page displaying a ransom note after encrypting local files on Android Chrome.HIGH
Malware

Browser-Only Ransomware Exploits Chrome File System API via

Check Point Research found a DeepSeek-generated sample using Chrome's File System Access API to encrypt Android photo directories — no native payload or exploit required.

4 min read
Chrome 148.0.7778.168 Patches Two High-Severity OOB Read FlawsHIGH
Vulnerabilities

Chrome 148.0.7778.168 Patches Two High-Severity OOB Read Flaws

Google Chrome 148.0.7778.168 fixes CVE-2026-8543 and CVE-2026-8541 — two high-severity out-of-bounds read vulnerabilities in FileSystem and UI components on Mac and all platforms.

CVE-2026-8543CVE-2026-8541
4 min read
Chrome 148 Patches AI Site Isolation Bypass, Android Payment FlawHIGH
Vulnerabilities

Chrome 148 Patches AI Site Isolation Bypass, Android Payment Flaw

CVE-2026-8568 (CVSS 3.1) lets attackers bypass Chrome Site Isolation via AI features after renderer compromise; CVE-2026-8566 (CVSS 4.3) targets Android Payments.

CVE-2026-8568CVE-2026-8566
3 min read
Chrome 148 Patches ANGLE Data Leak, Google Lens UAFHIGH
Vulnerabilities

Chrome 148 Patches ANGLE Data Leak, Google Lens UAF

Google fixed CVE-2026-8556 (ANGLE cross-origin leak) and CVE-2026-8550 (Google Lens use-after-free) in Chrome 148.0.7778.168 for Windows. Both flaws require a compromised renderer.

CVE-2026-8556CVE-2026-8550
4 min read
Chrome 148 Patches 79 Flaws, 14 Critical Including Heap OverflowCRITICAL
Vulnerabilities

Chrome 148 Patches 79 Flaws, 14 Critical Including Heap Overflow

Google's Chrome 148 update fixes 79 vulnerabilities, 14 critical — including heap buffer overflow CVE-2026-8509 ($43K bounty) and integer overflow CVE-2026-8510 in Skia ($25K...

CVE-2026-8509CVE-2026-8510
4 min read
Chrome 148 Patches 127 Flaws, Three Critical Use-After-Free BugsCRITICAL
Vulnerabilities

Chrome 148 Patches 127 Flaws, Three Critical Use-After-Free Bugs

Google's Chrome 148 fixes 127 vulnerabilities including three critical-severity bugs (CVE-2026-7896, CVE-2026-7897, CVE-2026-7898) — integer overflow in Blink and use-after-free...

CVE-2026-7896CVE-2026-7897CVE-2026-7898
3 min read
Chrome 147, Firefox 150 Patch Critical Code Execution FlawsCRITICAL
Industry News

Chrome 147, Firefox 150 Patch Critical Code Execution Flaws

Google and Mozilla ship Chrome 147 and Firefox 150 to fix critical and high-severity vulnerabilities enabling arbitrary code execution. Users urged to update immediately.

2 min read
108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram DataHIGH
Malware

108 Malicious Chrome Extensions Hijack Browsers, Steal Google and Telegram Data

Socket identified 108 malicious Chrome extensions that infected 20,000 users, stealing Google and Telegram session cookies and injecting ads via a shared command-and-control server.

3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.