Security dossiers

Chrome

Chrome security: zero-days, browser updates and exploitation reports. Compare individual advisories and follow how our coverage develops.

Scope and limits

Articles are selected by explicit product mentions in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.

Coverage timeline

  1. BlueMoon Exploit Kit Gives Four Espionage Groups a Shared Chrome-to-Windows Attack Chain

    Four espionage groups use BlueMoon exploit kit chaining Chrome V8 flaws and Windows ALPC bug to escape sandbox and deploy payloads.

  2. Fortinet Fixes Critical Authentication Flaws in FortiMonitorOnSight and Chrome Extension

    Fortinet patched 10 flaws, including critical JWT auth bypass in FortiMonitorOnSight and Chrome extension proxy bug. Update FortiPAM and extension now.

  3. Chrome V8 Zero-Day Exploited in Active Attacks: Update to Version 153 Now

    Google fixes actively exploited Chrome V8 zero-day CVE-2026-87491 plus 229 flaws. Update to Chrome 153.0.8010.36/37 and restart now.

  4. PEEP Turns Chrome and Edge Into Persistent Backdoors After a Host Breach

    PEEP is a post-exploitation framework that turns Chrome and Edge into persistent backdoors to steal cookies, monitor browsing, and run OS commands.

  5. Chrome Fixes Sixth Zero-Day of 2026: Active Attacks Target V8 Engine

    Google patched CVE-2026-85046, a V8 type confusion zero-day exploited in the wild. Update Chrome to 152.0.7977.82+ immediately to stay protected.

  6. Chrome and Edge Extensions Turned into Malware: 19 Modules to Steal Crypto, Seed Phrases, and Sessions

    Discover how 19 malicious modules in Chrome and Edge extensions steal crypto, seed phrases, and sessions. Learn immediate steps to secure your accounts.

  7. Chrome 151 Fixes 41 Vulnerabilities, Including Six Critical Flaws

    Chrome 151 update addresses 41 security vulnerabilities, including six critical flaws, to enhance browser safety and prevent potential exploits.

  8. Chrome prepares a shield against extensions pretending to be “managed by your organization”

    Google Chrome is adding a feature to block malicious extensions forced via local policies that hijack browsers and display managed by your organization.

  9. Over 1,800 patches in seven months: Google’s AI transforms Chrome security and finds a 13-year-old vulnerability

    Google's Gemini-based AI fixed over 1,800 Chrome vulnerabilities in seven months, discovering a 13-year-old sandbox escape flaw and automating patches.