< Back to situation

[REVISION HISTORY]

Browser extension malware and Chrome security overhaul

Updated 13 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-08 21:58 UTC → 2026-09-09 11:34 UTC · added removed

Following the June 2026 discovery of a Turkish-linked malware campaign involving 152 Chrome wallpaper extensions and an emergency patch for a V8 zero-day (CVE-2026-11645), Google began a significant security overhaul. This included the release of Chrome 150, which retired Manifest V2 and introduced several security and UI updates. In late July and August, Google accelerated its vulnerability remediation through the integration of Gemini AI agents. These tools identified over 1,000 security flaws, including a sandbox-escape vulnerability (CVE-2026-3545) that had existed for 13 years. While many bugs were uncovered, only 14 were reported as actively exploited. The AI-driven workflow successfully closed 1,072 issues within 60 days, reducing average fix times from 45 days to under a week and cutting manual effort by approximately 40%. To manage this increased discovery rate, Google transitioned to a two-week major-release cadence starting in September 2026 and began testing the delivery of two security updates per week. Chrome 151 introduced a native vertical tab option and addressed 15 vulnerabilities, including critical buffer overflows in WebGL and Dawn. Chrome 152 followed with 327 fixes, addressing 10 critical memory-safety issues and several ‘use-after-free’ flaws, such as CVE-2026-79282 in the ANGLE layer. In early September 2026, Google released further updates to address 26 vulnerabilities, including two critical use-after-free flaws: CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL, both of which could allow code execution outside the sandbox. Shortly after, Google patched a high-severity type confusion flaw in the V8 engine (CVE-2026-85046) that was being actively exploited in the wild. This marked the sixth actively exploited Chrome zero-day of 2026. The vulnerability, which affects other Chromium-based browsers, led CISA to add it to its Known Exploited Vulnerabilities catalog.

Versions

  1. 2026-09-09 11:34 UTC Browser extension malware and Chrome security overhaul
  2. 2026-09-08 21:58 UTC Browser extension malware and Chrome security overhaul
  3. 2026-09-06 18:30 UTC Browser extension malware and Chrome security overhaul
  4. 2026-09-04 23:36 UTC Browser extension malware and Chrome security overhaul
  5. 2026-08-28 07:50 UTC Browser extension malware and Chrome security overhaul
  6. 2026-08-26 09:15 UTC Browser extension malware and Chrome security overhaul
  7. 2026-08-20 00:34 UTC Browser extension malware and Chrome security overhaul
  8. 2026-08-08 16:51 UTC Browser extension malware and Chrome security overhaul
  9. 2026-08-03 18:15 UTC Browser extension malware and Chrome security overhaul
  10. 2026-08-02 08:08 UTC Browser extension malware and Chrome security overhaul
  11. 2026-08-01 08:45 UTC Browser extension malware and Chrome security overhaul
  12. 2026-07-31 18:24 UTC Browser extension malware and Chrome security overhaul
  13. 2026-07-31 17:13 UTC Browser extension malware and security responses
  14. 2026-07-31 15:04 UTC Browser extension malware and security responses

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.