Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
12 clusters · 65 sources · 52 days · First seen · Last updated
Categories: TECHNOLOGY
Browser extension malware and Chrome security overhaul
Entities: Gemini (Google AI model) · Google LLC · Google Chrome · Chrome web browser · Gemini AI
Overview
The coordinated campaign of fraudulent Chrome and Edge extensions uncovered in June 2026 prompted rapid security actions. Microsoft removed 119 malicious Edge add‑ons and suspended over 90 developer accounts, while Google responded with Chrome 150.0.7871.46/47, retiring Manifest V2, adding HTTPS‑first connections, deeper Wallet integration and the Gemini Spark AI assistant, and a $319 000 bug‑bounty that covered 433 fixes, including 20 critical bugs.
July emergency builds patched 12 high‑severity CVEs across Chrome 150.0.7871.128‑.182, and other vendors released related updates. On 29 July Google announced a security overhaul, fixing 1,072 bugs across versions 149 and 150—more than the total of the prior 23 releases—and uncovering a 13‑year‑old sandbox‑escape (CVE‑2026‑3545). The firm moved to a two‑week major‑release cadence, began bi‑weekly security updates, and piloted “dynamic patching” that replaces background processes without a full restart.
A pilot announced on 31 July confirmed the AI‑driven workflow: Gemini‑powered agents scan code, generate fixes and run automated tests, enabling a twice‑weekly release cadence for major milestones and weekly security patches. Chrome 151, released earlier in July, incorporated 370 additional fixes, including seven critical ones, using the dynamic‑patching system that leverages Chrome’s multi‑process architecture to swap child processes on the fly, keeping the browser continuously up‑to‑date for billions of users worldwide. The accelerated two‑week cycle will start with Chrome 153 in September 2026, mirroring Microsoft Edge, to counter AI‑powered attacks that exploit newly released patches.
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 14 SOURCES] Google fixed 1,072 security bugs in Chrome versions 149 and 150. (Google)
- [● 8 SOURCES] The 1,072 bugs exceed the total number fixed across the previous 23 Chrome milestone releases. (Google)
- [● 7 SOURCES] Google is developing dynamic patching that can apply Chrome updates without a full browser restart. (multiple)
- [● 7 SOURCES] A Gemini‑powered AI agent discovered a critical sandbox‑escape vulnerability (CVE‑2026‑3545) that had been present for 13 years. (multiple)
- [● 6 SOURCES] Google is piloting a twice‑weekly update cadence for Chrome. (multiple)
- [● 6 SOURCES] Dynamic patching leverages Chrome’s multi‑process architecture to replace background child processes on the fly. (multiple)
Timeline
-
1 day ago
[TECHNOLOGY] 13 sourcesGoogle Chrome to Adopt AI‑Driven Dynamic Patching and Twice‑Weekly UpdatesGoogle plans dynamic patching for Chrome, eliminating restarts, and will move to twice‑weekly, two‑week releases after AI‑found 1,072 fixes and a 13‑year‑old sandbox bug.
-
3 days ago
[TECHNOLOGY] 21 sourcesGoogle Chrome security overhaul: 1,072 bugs fixed and dynamic patching in developmentGoogle fixed 1,072 Chrome bugs in versions 149‑150, exceeds prior 23 releases, and is adding AI‑driven dynamic patching, a two‑week release cycle, and twice‑weekly security updates; Chrome 151 adds 370 fixes.
-
11 days ago
[TECHNOLOGY] 3 sourcesGoogle Chrome receives security patch and launches 64‑bit portable editionGoogle Chrome version 150.0.7871.182 fixes 12 security flaws and introduces a 64‑bit portable edition that runs from external drives.
-
12 days ago
[TECHNOLOGY] 3 sourcesGoogle Chrome 150 patch addresses critical memory vulnerabilitiesGoogle’s Chrome 150 update fixes seven memory bugs—including three critical use‑after‑free flaws and a V8 out‑of‑bounds error reported by OpenAI’s Codex Security—across Windows, macOS and Linux.
-
13 days ago
[TECHNOLOGY] 2 sourcesBrowsers patch critical flaws; Google, Microsoft remove ModHeaderGoogle, Microsoft and other vendors issued emergency patches for critical Chrome, Firefox, 7‑Zip and other software, while also removing the ModHeader extension after a hidden spying code was discovered.
-
17 days ago
[TECHNOLOGY] 2 sourcesGoogle Chrome 150 patches critical flaws as release cadence shifts to two‑week cycleGoogle Chrome 150, released June 30 2026, fixes 15 flaws including two critical Ozone bugs, and introduces a two‑week release cycle with Chrome 153 slated for September 8.
-
23 days ago
[TECHNOLOGY] 10 sourcesGoogle Chrome 150 adds back button and menu overhaul to AndroidChrome 150 for Android arrives with a new back button, revamped menu, 433 security fixes and a built‑in Gemini Spark AI assistant, rolling out globally via the Play Store in July 2026.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesGoogle releases major Chrome update fixing 400 flaws and patches exploited Android zero‑dayGoogle's Chrome 150 update patches nearly 400 flaws, while its Android bulletin fixes a actively exploited zero‑day, marking the fourth such patch in six months.
-
about 1 month ago
[TECHNOLOGY] 11 sourcesMicrosoft Removes 119 Malicious Edge Extensions for Credential Theft and Ad FraudMicrosoft removed 119 malicious Edge extensions (StegoAd) that hid code in images/fonts, stole credentials and ran ad fraud, affecting up to 2.6 million users; users urged to check extensions and resetPasswords
-
about 2 months ago
[TECHNOLOGY] 2 sourcesGoogle removes 152 malicious Chrome wallpaper extensionsResearchers found 152 Chrome wallpaper extensions that stole user data and forged Google search clicks; Google has removed them after a coordinated ad‑fraud campaign linked to Turkey.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesGoogle Chrome confronted with stealthy data‑collecting extensions and an active zero‑day exploitSocket flagged 152 Chrome extensions that secretly collect user data, while Google warns of an actively exploited zero‑day (CVE‑2026‑11645) and pushes an urgent update.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesGoogle patches actively exploited Chrome zero‑day vulnerabilityGoogle released Chrome 149.0.7827 update fixing 74 bugs, including actively exploited CVE‑2026‑11645 in V8, urging users to update and restart immediately.
Sources
all-about-security.de · android-mt.ouest-france.fr · androidportal.zoznam.sk · androidworld.nl · archynetys.com · asaaseradio.com · bitnewsbot.com · blog.clavis.com.br · blog.pradeo.com · blogspan.net · borncity.com · boygeniusreport.com · browserhow.com · ceotech.it · chip.de · classics.itmedia.co.jp · clubic.com · computerwoche.de · cyber-securite.fr · cyberinsider.com · cybersecuritynews.com · diarioestrategia.cl · diarioti.com · filehorse.com · finance.technews.tw · fonetech.cz · fosspost.org · gaming.hwupgrade.it · generation-nt.com · gigazine.net · googlediscovery.com · hackernews.com · hawkdive.com · hothardware.com · it-boltwise.de · it-daily.net · ithome.com · malwarebytes.org · meeco.kr · mobility.smartworld.it · netthings.pt · nokiapoweruser.com · phonandroid.com · planningassociates.com.au · primorska.info · punto-informatico.it · sarenacreates.com · schmidtisblog.de
This summary has been updated 3 times: see revision history