Products

Google Chrome

Follow the latest coverage, related explainers and connected technology stories.

Latest coverage

CN
Compromise of Three Top-Level Domains Enabled the Issuance of Fake TLS Certificates for Google and Major Services

Compromise of Three Top-Level Domains Enabled the Issuance of Fake TLS Certificates for Google and Major Services

Attackers exploited control of the .gh, .sl, and .as domains to modify DNS records and pass automated validation processes, then obtain unauthorized TLS certificates for domains belonging to Google and other global brands. Chrome blocked the certificates identified by Google, but the company warned that browser-level intervention does not protect all users or guarantee the detection of every certificate.

CN
BragJack Attack Hijacks Browser AI Agents via a Malicious Extension

BragJack Attack Hijacks Browser AI Agents via a Malicious Extension

Security researcher Gal Weizman revealed a proof-of-concept technique called BragJack that exploits a malicious browser extension to take control of artificial intelligence assistants in five browsers and services, potentially enabling the reading of files and browsing data and the execution of actions on behalf of the user. The research earned more than $20,000 in bug bounty rewards and resulted in CVE assignments.

CN
Banking Malware Bypasses Chromium Checks to Force Malicious Extensions onto Chrome and Edge

Banking Malware Bypasses Chromium Checks to Force Malicious Extensions onto Chrome and Edge

An active banking operation since mid-2025 has used the KREMLIN tool to install malicious extensions on Chrome and Edge without user consent, aiming to steal passwords, tokens, sessions, and sensitive data. Elastic Security Labs identified approximately 1,515 infected systems, most of them in Brazil, and managed to disrupt the current campaign by exploiting an anti-analysis check.

CN
Chrome Shortens Its Update Release Cycle to Two Weeks to Accelerate Vulnerability Remediation

Chrome Shortens Its Update Release Cycle to Two Weeks to Accelerate Vulnerability Remediation

Google has begun releasing Chrome on a two-week cycle instead of a four-week cycle, with Chrome 153 launching for desktop, iOS, and Android. The company links the move to the need to narrow the gap between discovering vulnerabilities and delivering fixes to users, as threats accelerate and artificial intelligence tools evolve.

CN
Malicious Chrome and Edge Extensions Stole Cryptocurrency and Browser Data

Malicious Chrome and Edge Extensions Stole Cryptocurrency and Browser Data

Socket uncovered a campaign that used 19 extensions for Google Chrome and Microsoft Edge to distribute a malicious software framework capable of stealing cryptocurrency, account data, and browsing history, while injecting fraudulent ClickFix pages. The investigation’s findings indicate that the activity may have started as early as the beginning of 2024, and that some extensions became malicious tools after attackers acquired them and automatically updated them.