Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic.
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap.
The post Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic.
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap.
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now.
The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.
With Chrome, Google pioneered the rapid release model for browser security. Now, Google says updates may need to change in the face of AI security analysis. According to the company, the number of bug fixes in Chrome releases has skyrocketed in recent months because AI is detecting so many flaws. We could be looking at more frequent updates soon, but Google is also working on ways to get those updates rolled out without bothering you as much.
Google has released two major Chrome milestone builds
With Chrome, Google pioneered the rapid release model for browser security. Now, Google says updates may need to change in the face of AI security analysis. According to the company, the number of bug fixes in Chrome releases has skyrocketed in recent months because AI is detecting so many flaws. We could be looking at more frequent updates soon, but Google is also working on ways to get those updates rolled out without bothering you as much.
Google has released two major Chrome milestone builds recently—Chrome 149 in early June and Chrome 150 just a few weeks later. These two updates had a total of 1,072 bug fixes, which is more than the previous 23 releases combined. Such is the impact of giant cybersecurity AI models that can probe software for vulnerabilities at light speed. Some of these vulnerabilities were serious, too, with one bug hiding in the Chrome codebase for 13 years. If it had been exploited, an attacker could have bypassed the Chrome sandbox to make the browser access local files.
Number of security bugs fixed in recent Chrome Stable release milestones.
Credit:
Google
With the vastly higher rate of vulnerability identification, Google is worried bad actors will also be able to identify software flaws faster. Its goal is to ensure your Chrome install is always up to date or as close to it as possible. The first step toward that is the two-week update cycle the company announced earlier in 2026, but it's now piloting a system that would update Chrome twice per week. This would get patches out the door faster, ensuring that browsers are ready for the threat of AI-fueled attacks.
DuckDuckGo’s web browser, often referred to as the DuckDuckGo Privacy Browser, can now block video ads, including in-video ads on YouTube.
The post DuckDuckGo Now Blocks Most Video Ads on Windows, Mac, iPhone appeared first on TechRepublic.
Google released a Chrome update addressing 382 security bugs, including sandbox-escape risks. Users and IT teams should update quickly.
The post New Chrome Update Fixes 382 Security Bugs Across Desktop, Mobile appeared first on TechRepublic.
LayerX found that BioShocking could trick AI browsers into leaking credentials by disguising malicious prompts as game rules.
The post New BioShocking Attack Tricks AI Browsers Into Leaking Credentials appeared first on TechRepublic.
Microsoft found a fake Perplexity AI Chrome extension that rerouted searches through attacker servers. Here’s what users should check now.
The post Microsoft Warns: Fake Perplexity Extension Abused Chrome Search Features appeared first on TechRepublic.
Google’s Chrome 149 security update fixes 18 bugs, including four critical flaws affecting WebGL, Autofill, and Blink components.
The post Update Chrome Now: Google Fixes 18 Security Flaws, Including Critical Bugs appeared first on TechRepublic.
Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said.
The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thre
Extensions installed on almost 1 million devices have been overriding key security protections to turn browsers into engines that scrape websites on behalf of a paid service, a researcher said.
The 245 extensions, available for Chrome, Firefox, and Edge, have racked up nearly 909,000 downloads, John Tuckner of SecurityAnnex reported. The extensions serve a wide range of purposes, including managing bookmarks and clipboards, boosting speaker volumes, and generating random numbers. The common thread among all of them: They incorporate MellowTel-js, an open source JavaScript library that allows developers to monetize their extensions.
Intentional weakening of browsing protections
Tuckner and critics say the monetization works by using the browser extensions to scrape websites on behalf of paying customers, which include AI startups, according to MellowTel founder Arsian Ali. Tuckner reached this conclusion after uncovering close ties between MellowTel and Olostep, a company that bills itself as "the world's most reliable and cost-effective Web scraping API." Olostep says its service “avoids all bot detection and can parallelize up to 100K requests in minutes.” Paying customers submit the locations of browsers they want to access specific webpages. Olostep then uses its installed base of extension users to fulfill the request.
As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices.
The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sen
As many of us celebrated the year-end holidays, a small group of researchers worked overtime tracking a startling discovery: At least 33 browser extensions hosted in Google’s Chrome Web Store, some for as long as 18 months, were surreptitiously siphoning sensitive data from roughly 2.6 million devices.
The compromises came to light with the discovery by data loss prevention service Cyberhaven that a Chrome extension used by 400,000 of its customers had been updated with code that stole their sensitive data.
’Twas the night before Christmas
The malicious extension, available as version 24.10.4, was available for 31 hours, from December 25 at 1:32 AM UTC to Dec 26 at 2:50 AM UTC. Chrome browsers actively running Cyberhaven during that window would automatically download and install the malicious code. Cyberhaven responded by issuing version 24.10.5, and 24.10.6 a few days later.