Skip to main content
← All Articles

Tag

#Browser Security

35 articles

Advertisement

Malicious Chrome VPN Extensions Route Traffic via SOCKS5 Proxies
HIGH
Malware

Malicious Chrome VPN Extensions Route Traffic via SOCKS5 Proxies

Over 730 free Chrome VPN extensions are redirecting user browser traffic through SOCKS5 proxies, enabling man-in-the-middle attacks and data interception.

Runtime Rebel Intel
4 min read · Aug 12, 2026
AI Browser Prompt Injection Flaws Defeat Vendor Guardrails
MEDIUM
Vulnerabilities

AI Browser Prompt Injection Flaws Defeat Vendor Guardrails

New security research reveals that AI-powered web browsers remain susceptible to persistent prompt injection flaws despite guardrails.

Runtime Rebel Intel
3 min read · Aug 9, 2026
LOW
Threat Intel

Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices

Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.

Runtime Rebel Intel
4 min read · Aug 2, 2026
Google Chrome Updates Resolve 1,442 Security Flaws
LOW
Vulnerabilities

Google Chrome Updates Resolve 1,442 Security Flaws

Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.

Runtime Rebel Intel
4 min read · Jul 31, 2026
MEDIUM
Malware

JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses

Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.

Runtime Rebel Intel
4 min read · Jul 25, 2026
HIGH
Vulnerabilities

Anthropic Claude Chrome Extension: Malicious AI Action Trigger

A flaw in Anthropic's Claude for Chrome extension enables malicious extensions to trigger AI actions, potentially abusing access to connected services like Gmail, Google…

Runtime Rebel Intel
4 min read · Jul 16, 2026

Advertisement

SASE AI Blind Spot: Why Packet Inspection Fails Modern Workflows
MEDIUM
Cloud Security

SASE AI Blind Spot: Why Packet Inspection Fails Modern Workflows

Enterprise data leakage via generative AI tools and browser extensions exposes critical flaws in traditional SASE models that rely solely on packet inspection.

Runtime Rebel Intel
4 min read · Jul 15, 2026
CRITICAL
Vulnerabilities

Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws

Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.

Runtime Rebel Intel
4 min read · Jul 9, 2026
INFO
Threat Intel

DuckDuckGo Browser Enhances Privacy with YouTube Ad Blocking

DuckDuckGo's privacy-focused browser now blocks most YouTube video ads, bolstering user privacy against tracking and unwanted commercial interruptions.

Runtime Rebel Intel
4 min read · Jul 8, 2026
Opera GX Mod Auto-Installation Vulnerability Analysis
HIGH
Vulnerabilities

Opera GX Mod Auto-Installation Vulnerability Analysis

A critical flaw in Opera GX allowed malicious sites to auto-install mods and exfiltrate sensitive data. Learn how to detect and mitigate this browser threat.

Runtime Rebel Intel
4 min read · Jul 6, 2026
Malicious Perplexity Chrome Extension Intercepts User Data
HIGH
Threat Intel

Malicious Perplexity Chrome Extension Intercepts User Data

A malicious Chrome extension impersonating Perplexity AI intercepted user search queries and address bar inputs, routing them via attacker infrastructure, posing a…

Runtime Rebel Intel
4 min read · Jun 29, 2026
Microsoft Pulls 119 Malicious StegoAd Edge Extensions
MEDIUM
Malware

Microsoft Pulls 119 Malicious StegoAd Edge Extensions

Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.

Runtime Rebel Intel
3 min read · Jun 29, 2026
"Adblock for YouTube" Extension: Dormant Script Injection Threat
HIGH
Malware

"Adblock for YouTube" Extension: Dormant Script Injection Threat

A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.

Runtime Rebel Intel
4 min read · Jun 25, 2026
HIGH
Vulnerabilities

Chrome 149 Update Patches 18 High-Severity UAF Vulnerabilities

Google releases Chrome 149 to address 18 severe vulnerabilities, including multiple use-after-free defects in Graphics, Dawn, and Mojo components.

Runtime Rebel Intel
4 min read · Jun 25, 2026
Malicious Chrome Wallpaper Extensions Distribute Adware
HIGH
Malware

Malicious Chrome Wallpaper Extensions Distribute Adware

Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts.

Runtime Rebel Intel
4 min read · Jun 15, 2026
HIGH
Vulnerabilities

Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide

Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.

Runtime Rebel Intel
3 min read · Jun 12, 2026
CRITICAL
Vulnerabilities

Google Patches CVE-2026-11645: 5th Chrome Zero-Day Exploited in 2026

Google addresses CVE-2026-11645, a critical zero-day vulnerability in Chrome being actively exploited. Learn about patch guidance and detection strategies.

Runtime Rebel Intel
4 min read · Jun 9, 2026
INFO
Threat Intel

2026 Verizon DBIR Analysis: Securing the Browser Against Phishing

The 2026 Verizon DBIR identifies browser-layer security gaps as a primary threat vector, highlighting risks from phishing, shadow AI, and malicious extensions.

Runtime Rebel Intel
3 min read · Jun 5, 2026
INFO
Threat Intel

Brave Origin: Reducing Browser Attack Surface via Paid Minimalism

Brave Software launches Brave Origin, a subscription-based minimalist browser that removes AI, crypto, and VPN features to prioritize privacy and performance.

Runtime Rebel Intel
4 min read · Jun 5, 2026
HIGH
Vulnerabilities

Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript

Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.

Runtime Rebel Intel
4 min read · May 21, 2026
INFO
Threat Intel

Microsoft Edge: Hardening Against Cleartext Password Exposure

Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.

Runtime Rebel Intel
4 min read · May 15, 2026
MEDIUM
Threat Intel

Bypassing Enterprise DLP via Browser-Based Data Exfiltration

Examine how modern SaaS workflows and generative AI prompts bypass traditional DLP, creating significant visibility gaps in enterprise security posture.

Runtime Rebel Intel
4 min read · May 7, 2026
MEDIUM
Vulnerabilities

Microsoft Edge Cleartext Password Exposure Risks — Mitigation Guide

Critical analysis of Microsoft Edge credential storage risks. Learn how to prevent cleartext password extraction and secure browser-based identities.

Runtime Rebel Intel
4 min read · May 5, 2026
HIGH
Vulnerabilities

Firefox 150 Patch: 271 Zero-Days Found via Claude Mythos — Update Now

Firefox 150 addresses 271 vulnerabilities discovered by Anthropic’s Claude Mythos AI model, highlighting a shift in automated vulnerability discovery.

Runtime Rebel Intel
4 min read · Apr 29, 2026