Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 2 sources · 18 days · First seen · Last updated
Google Chrome account security threats
Overview
In July 2026 a security firm reported that attackers could exploit Google Chrome’s sync feature to silently monitor a victim’s browsing activity. By adding their own account to a compromised device or Google account, they could capture history, searches, bookmarks, autofill data and open tabs without the user’s knowledge, enabling prolonged cyberstalking and targeted espionage.
By early August 2026 researchers observed a surge in session‑cookie hijacking that allowed attackers to bypass passwords and two‑factor authentication for Google and Microsoft accounts. Nearly 94 billion stolen browser cookies were found on underground markets, with about 20 % still active. Malware families such as RedLine, Vidar and LummaC2 harvest these cookies, and Chrome’s default “sync everything” setting further amplifies the risk by aggregating passwords, payment data and browsing history under a single Google account. Security advice across both reports emphasizes strong passwords, two‑factor authentication, reviewing connected devices, customizing or disabling Chrome sync for sensitive data, and using password managers or passkeys for stronger protection.
Entities
Timeline
-
16 days ago
[TECHNOLOGY] 2 sourcesSession cookie hijacking endangers Google accounts worldwideSession‑cookie hijacking, fueled by billions of stolen cookies and malware, threatens Google and Microsoft accounts; users should customize Chrome sync to limit exposure.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesChrome Sync Exploited for Silent Surveillance, Security Firm FindsSecurity firm Certo warns that attackers can misuse Chrome Sync to silently track browsing data, enabling covert surveillance and cyberstalking.
Sources
fashionsublime.com · semplice.it