Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
20 clusters · 91 sources · 96 days · First seen · Last updated
Browser extension malware and Chrome security overhaul
Overview
Following the June 2026 discovery of a Turkish-linked malware campaign involving 152 Chrome wallpaper extensions and an emergency patch for a V8 zero-day (CVE-2026-11645), Google began a significant security overhaul. This included the release of Chrome 150, which retired Manifest V2 and introduced several security and UI updates. In late July and August, Google accelerated its vulnerability remediation through the integration of Gemini AI agents. These tools identified over 1,000 security flaws, including a sandbox-escape vulnerability (CVE-2026-3545) that had existed for 13 years. While many bugs were uncovered, only 14 were reported as actively exploited. The AI-driven workflow successfully closed 1,072 issues within 60 days, reducing average fix times from 45 days to under a week and cutting manual effort by approximately 40%. To manage this increased discovery rate, Google transitioned to a two-week major-release cadence starting in September 2026 and began testing the delivery of two security updates per week. Chrome 151 introduced a native vertical tab option and addressed 15 vulnerabilities, including critical buffer overflows in WebGL and Dawn. Chrome 152 followed with 327 fixes, addressing 10 critical memory-safety issues and several ‘use-after-free’ flaws, such as CVE-2026-79282 in the ANGLE layer. In early September 2026, Google released further updates to address 26 vulnerabilities, including two critical use-after-free flaws: CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL, both of which could allow code execution outside the sandbox. Shortly after, Google patched a high-severity type confusion flaw in the V8 engine (CVE-2026-85046) that was being actively exploited in the wild. This marked the sixth actively exploited Chrome zero-day of 2026. The vulnerability, which affects other Chromium-based browsers, led CISA to add it to its Known Exploited Vulnerabilities catalog.
Entities
Google · Chrome · Google Chrome · Chromium · Gemini AI
Claims
What the coverage asserts, and how many sources carry each claim.
Coverage disagrees
Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.
-
"Google is piloting a twice‑weekly update cadence for Chrome."
vs
"Google plans to shift Chrome to a two‑week release cycle."
One claim states Google is piloting a twice-weekly update cadence, while the other states they plan to shift to a two-week release cycle.
- [DISPUTED] Google is piloting a twice‑weekly update cadence for Chrome.
- [DISPUTED] Google plans to shift Chrome to a two‑week release cycle.
- [● 14 SOURCES] Google fixed 1,072 security bugs in Chrome versions 149 and 150.
- [● 13 SOURCES] Two Windows vulnerabilities, CVE-2026-85880 and CVE-2026-81963, are being actively exploited in the wild. cyberinsider.com · www.blogspan.net · cybernoz.com · australiancybersecuritymagazine.com.au · japan.zdnet.com · +8 more
- [● 11 SOURCES] The V8 vulnerability allows remote attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. cybernoz.com · revistametronomo.com · techplanet.today · www.chiccheinformatiche.com · www.iphoneincanada.ca · +6 more
- [● 11 SOURCES] Microsoft released security updates in September 2026 addressing 974 CVEs, including 723 affecting Windows. cyberinsider.com · www.blogspan.net · cybernoz.com · australiancybersecuritymagazine.com.au · www.ithome.com · +6 more
- [● 9 SOURCES] Google’s Gemini‑powered AI agents discovered a sandbox‑escape vulnerability (CVE‑2026‑3545) that had existed for 13 years.
- [● 9 SOURCES] Google released a security update for Chrome to fix 12 vulnerabilities. cybernoz.com · www.it-boltwise.de · revistametronomo.com · borncity.com · thenextweb.com · +4 more
- [● 9 SOURCES] CVE-2026-85046 has been assigned a CVSS score of 8.8. cybernoz.com · www.it-boltwise.de · revistametronomo.com · borncity.com · techplanet.today · +4 more
- [● 7 SOURCES] Google is developing dynamic patching that can apply Chrome updates without a full browser restart.
- [● 7 SOURCES] CVE-2026-85046 is the sixth actively exploited Chrome zero-day of 2026. cybernoz.com · borncity.com · thenextweb.com · www.chiccheinformatiche.com · www.iphoneincanada.ca · +2 more
Timeline
-
3 days ago
[TECHNOLOGY] 2 sourcesGoogle Chrome releases urgent security update to patch active exploitsGoogle released Chrome 153 to patch 230 vulnerabilities, including a critical JavaScript V8 flaw currently being exploited in the wild. Users are urged to update immediately.
-
7 days ago
[TECHNOLOGY] 11 sourcesGoogle issues critical security updates for Chrome and AndroidGoogle has issued critical security updates for Chrome and Android, patching hundreds of vulnerabilities, including an actively exploited zero-day flaw in the Chrome V8 engine and several remote code execution'
-
12 days ago
[TECHNOLOGY] 15 sourcesGoogle Chrome patches actively exploited V8 zero-day vulnerabilityGoogle has patched a high-severity zero-day vulnerability (CVE-2026-85046) in the Chrome V8 engine that is being actively exploited. The flaw affects all Chromium-based browsers, including Microsoft Edge.
-
14 days ago
[TECHNOLOGY] 3 sourcesGoogle Chrome releases update to fix critical security vulnerabilitiesGoogle has released a Chrome update addressing 26 security flaws, including two critical use-after-free vulnerabilities in Shared Tab Groups and WebGL that could allow remote code execution.
-
21 days ago
[TECHNOLOGY] 10 sourcesGoogle Chrome 152 released with 327 security fixesGoogle has released Chrome 152, patching 327 security vulnerabilities, including 10 critical flaws that could allow remote code execution. The update also introduces new APIs and post-quantum cryptography.
-
28 days ago
[TECHNOLOGY] 3 sourcesGoogle Chrome introduces vertical tabs and critical security updatesGoogle is updating Chrome with a new native vertical tab feature for better organization and a security patch for version 151 addressing 15 vulnerabilities, including two critical graphics-related flaws.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesGoogle releases Chrome 151 update amid rising cybersecurity threatsGoogle released Chrome 151 to fix 41 vulnerabilities, utilizing AI for patching, while researchers identified critical flaws in Enterprise Java middleware, including Bonita and Apache OFBiz.
-
about 1 month ago
[TECHNOLOGY] 4 sourcesAI security tools uncover 1,000+ Chrome bugs, but only a few are exploitedAI tools identified over 1,000 Chrome vulnerabilities, but only 14 were exploited; Google’s Gemini AI closed 1,072 bugs in 60 days, slashing fix times and manual effort.
-
about 2 months ago
[TECHNOLOGY] 13 sourcesGoogle Chrome AI agents enable record security fixes and dynamic patchingGoogle’s Gemini AI agents helped fix 1,072 Chrome bugs, uncovered a 13‑year‑old flaw, and are driving twice‑weekly updates and dynamic patching to reduce restart needs.
-
about 2 months ago
[TECHNOLOGY] 21 sourcesGoogle Chrome security overhaul: 1,072 bugs fixed and dynamic patching in developmentGoogle fixed 1,072 Chrome bugs in versions 149‑150, exceeds prior 23 releases, and is adding AI‑driven dynamic patching, a two‑week release cycle, and twice‑weekly security updates; Chrome 151 adds 370 fixes.
-
about 2 months ago
[TECHNOLOGY] 3 sourcesGoogle Chrome receives security patch and launches 64‑bit portable editionGoogle Chrome version 150.0.7871.182 fixes 12 security flaws and introduces a 64‑bit portable edition that runs from external drives.
-
about 2 months ago
[TECHNOLOGY] 3 sourcesGoogle Chrome 150 patch addresses critical memory vulnerabilitiesGoogle’s Chrome 150 update fixes seven memory bugs—including three critical use‑after‑free flaws and a V8 out‑of‑bounds error reported by OpenAI’s Codex Security—across Windows, macOS and Linux.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesBrowsers patch critical flaws; Google, Microsoft remove ModHeaderGoogle, Microsoft and other vendors issued emergency patches for critical Chrome, Firefox, 7‑Zip and other software, while also removing the ModHeader extension after a hidden spying code was discovered.
-
2 months ago
[TECHNOLOGY] 2 sourcesGoogle Chrome 150 patches critical flaws as release cadence shifts to two‑week cycleGoogle Chrome 150, released June 30 2026, fixes 15 flaws including two critical Ozone bugs, and introduces a two‑week release cycle with Chrome 153 slated for September 8.
-
2 months ago
[TECHNOLOGY] 10 sourcesGoogle Chrome 150 adds back button and menu overhaul to AndroidChrome 150 for Android arrives with a new back button, revamped menu, 433 security fixes and a built‑in Gemini Spark AI assistant, rolling out globally via the Play Store in July 2026.
-
3 months ago
[TECHNOLOGY] 2 sourcesGoogle releases major Chrome update fixing 400 flaws and patches exploited Android zero‑dayGoogle's Chrome 150 update patches nearly 400 flaws, while its Android bulletin fixes a actively exploited zero‑day, marking the fourth such patch in six months.
-
3 months ago
[TECHNOLOGY] 11 sourcesMicrosoft Removes 119 Malicious Edge Extensions for Credential Theft and Ad FraudMicrosoft removed 119 malicious Edge extensions (StegoAd) that hid code in images/fonts, stole credentials and ran ad fraud, affecting up to 2.6 million users; users urged to check extensions and resetPasswords
-
3 months ago
[TECHNOLOGY] 2 sourcesGoogle removes 152 malicious Chrome wallpaper extensionsResearchers found 152 Chrome wallpaper extensions that stole user data and forged Google search clicks; Google has removed them after a coordinated ad‑fraud campaign linked to Turkey.
-
3 months ago
[TECHNOLOGY] 2 sourcesGoogle Chrome confronted with stealthy data‑collecting extensions and an active zero‑day exploitSocket flagged 152 Chrome extensions that secretly collect user data, while Google warns of an actively exploited zero‑day (CVE‑2026‑11645) and pushes an urgent update.
-
3 months ago
[TECHNOLOGY] 2 sourcesGoogle patches actively exploited Chrome zero‑day vulnerabilityGoogle released Chrome 149.0.7827 update fixing 74 bugs, including actively exploited CVE‑2026‑11645 in V8, urging users to update and restart immediately.
Sources
ad-hoc-news.de · all-about-security.de · android-mt.ouest-france.fr · androidportal.zoznam.sk · androidworld.nl · archynetys.com · asaaseradio.com · b2b-cyber-security.de · bitnewsbot.com · blog.clavis.com.br · blog.pradeo.com · blogspan.net · borncity.com · boygeniusreport.com · browserhow.com · ceotech.it · chiccheinformatiche.com · chip.de · classics.itmedia.co.jp · clubic.com · computerbase.de · computerwoche.de · cryptobriefing.com · cyber-securite.fr · cyberinsider.com · cybernoz.com · cybersecurity-news.de · cybersecuritynews.com · deskmodder.de · diarioestrategia.cl · diarioti.com · digital.t-online.de · drweb.de · filehorse.com · finance.technews.tw · fonetech.cz · fosspost.org · gaming.hwupgrade.it · generation-nt.com · giga.de · gigazine.net · googlediscovery.com · hackernews.com · hawkdive.com · hothardware.com · infoguerra.com.br · invitehealth.substack.com · iphoneincanada.ca
This summary has been updated 13 times: see revision history