<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Browser Security</title><description>Cybersecurity articles tagged #Browser Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Malicious Chrome VPN Extensions Route Traffic via SOCKS5 Proxies</title><link>https://runtimerebel.com/blog/malicious-chrome-vpn-extensions-route-traffic-via-socks5-proxies</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-chrome-vpn-extensions-route-traffic-via-socks5-proxies</guid><description>Over 730 free Chrome VPN extensions are redirecting user browser traffic through SOCKS5 proxies, enabling man-in-the-middle attacks and data interception.</description><pubDate>Wed, 12 Aug 2026 16:46:46 GMT</pubDate><category>Chrome Extensions</category><category>VPN</category><category>Man-in-the-Middle</category><category>Browser Security</category><category>Proxy</category></item><item><title>AI Browser Prompt Injection Flaws Defeat Vendor Guardrails</title><link>https://runtimerebel.com/blog/ai-browser-prompt-injection-flaws-defeat-vendor-guardrails</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-browser-prompt-injection-flaws-defeat-vendor-guardrails</guid><description>New security research reveals that AI-powered web browsers remain susceptible to persistent prompt injection flaws despite guardrails.</description><pubDate>Sun, 09 Aug 2026 16:25:35 GMT</pubDate><category>Artificial Intelligence</category><category>Browser Security</category><category>Zero-Day</category><category>Application Security</category></item><item><title>Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices</title><link>https://runtimerebel.com/blog/google-chrome-blocks-malicious-new-tab-hijacker-extensions-on-unmanaged-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-blocks-malicious-new-tab-hijacker-extensions-on-unmanaged-devices</guid><description>Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.</description><pubDate>Sun, 02 Aug 2026 16:48:04 GMT</pubDate><category>Google Chrome</category><category>Browser Security</category><category>Malware</category><category>Extensions</category><category>Hijacking</category></item><item><title>Google Chrome Updates Resolve 1,442 Security Flaws</title><link>https://runtimerebel.com/blog/google-chrome-updates-resolve-1442-security-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-updates-resolve-1442-security-flaws</guid><description>Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.</description><pubDate>Fri, 31 Jul 2026 17:41:44 GMT</pubDate><category>Google Chrome</category><category>Browser Security</category><category>Vulnerability Patching</category><category>Security Update</category></item><item><title>JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses</title><link>https://runtimerebel.com/blog/javascript-smuggling-in-memory-malware-assembly-evades-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/javascript-smuggling-in-memory-malware-assembly-evades-defenses</guid><description>Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.</description><pubDate>Sat, 25 Jul 2026 16:59:37 GMT</pubDate><category>Javascript Smuggling</category><category>Infostealer</category><category>Browser Security</category><category>Vidar</category><category>StealC</category></item><item><title>Anthropic Claude Chrome Extension: Malicious AI Action Trigger</title><link>https://runtimerebel.com/blog/anthropic-claude-chrome-extension-malicious-ai-action-trigger</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-chrome-extension-malicious-ai-action-trigger</guid><description>A flaw in Anthropic&apos;s Claude for Chrome extension enables malicious extensions to trigger AI actions, potentially abusing access to connected services like Gmail, Google…</description><pubDate>Thu, 16 Jul 2026 21:02:07 GMT</pubDate><category>Anthropic</category><category>Claude</category><category>Chrome Extension</category><category>AI</category><category>Browser Security</category><category>API Abuse</category></item><item><title>SASE AI Blind Spot: Why Packet Inspection Fails Modern Workflows</title><link>https://runtimerebel.com/blog/sase-ai-blind-spot-why-packet-inspection-fails-modern-workflows</link><guid isPermaLink="true">https://runtimerebel.com/blog/sase-ai-blind-spot-why-packet-inspection-fails-modern-workflows</guid><description>Enterprise data leakage via generative AI tools and browser extensions exposes critical flaws in traditional SASE models that rely solely on packet inspection.</description><pubDate>Wed, 15 Jul 2026 13:46:55 GMT</pubDate><category>SASE</category><category>GenAI</category><category>Data Leakage</category><category>Browser Security</category><category>DLP</category></item><item><title>Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws</title><link>https://runtimerebel.com/blog/chrome-150-update-patching-27-vulnerabilities-critical-use-after-free-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-150-update-patching-27-vulnerabilities-critical-use-after-free-flaws</guid><description>Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.</description><pubDate>Thu, 09 Jul 2026 07:44:34 GMT</pubDate><category>Chrome 150</category><category>Use After Free</category><category>Browser Security</category><category>Vulnerability Patching</category><category>Google Chrome</category></item><item><title>DuckDuckGo Browser Enhances Privacy with YouTube Ad Blocking</title><link>https://runtimerebel.com/blog/duckduckgo-browser-enhances-privacy-with-youtube-ad-blocking</link><guid isPermaLink="true">https://runtimerebel.com/blog/duckduckgo-browser-enhances-privacy-with-youtube-ad-blocking</guid><description>DuckDuckGo&apos;s privacy-focused browser now blocks most YouTube video ads, bolstering user privacy against tracking and unwanted commercial interruptions.</description><pubDate>Wed, 08 Jul 2026 14:15:45 GMT</pubDate><category>DuckDuckGo</category><category>YouTube</category><category>Ad Blocking</category><category>Privacy</category><category>Tracking</category><category>Browser Security</category></item><item><title>Opera GX Mod Auto-Installation Vulnerability Analysis</title><link>https://runtimerebel.com/blog/opera-gx-mod-auto-installation-vulnerability-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/opera-gx-mod-auto-installation-vulnerability-analysis</guid><description>A critical flaw in Opera GX allowed malicious sites to auto-install mods and exfiltrate sensitive data. Learn how to detect and mitigate this browser threat.</description><pubDate>Mon, 06 Jul 2026 08:26:02 GMT</pubDate><category>Opera GX</category><category>Browser Security</category><category>Information Disclosure</category><category>Malicious Add Ons</category></item><item><title>Malicious Perplexity Chrome Extension Intercepts User Data</title><link>https://runtimerebel.com/blog/malicious-perplexity-chrome-extension-intercepts-user-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-perplexity-chrome-extension-intercepts-user-data</guid><description>A malicious Chrome extension impersonating Perplexity AI intercepted user search queries and address bar inputs, routing them via attacker infrastructure, posing a…</description><pubDate>Mon, 29 Jun 2026 20:41:15 GMT</pubDate><category>Chrome Extension</category><category>Perplexity AI</category><category>Data Interception</category><category>Browser Security</category><category>Microsoft Threat Intelligence</category><category>Google Chrome Web Store</category></item><item><title>Microsoft Pulls 119 Malicious StegoAd Edge Extensions</title><link>https://runtimerebel.com/blog/microsoft-pulls-119-malicious-stegoad-edge-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-pulls-119-malicious-stegoad-edge-extensions</guid><description>Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.</description><pubDate>Mon, 29 Jun 2026 09:51:08 GMT</pubDate><category>Microsoft Edge</category><category>StegoAd</category><category>Browser Security</category><category>Steganography</category><category>Adware</category></item><item><title>&quot;Adblock for YouTube&quot; Extension: Dormant Script Injection Threat</title><link>https://runtimerebel.com/blog/adblock-for-youtube-extension-dormant-script-injection-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/adblock-for-youtube-extension-dormant-script-injection-threat</guid><description>A popular Chrome ad blocker, &quot;Adblock for YouTube,&quot; with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.</description><pubDate>Thu, 25 Jun 2026 17:17:00 GMT</pubDate><category>Chrome Extension</category><category>Adblock for YouTube</category><category>Script Injection</category><category>JavaScript</category><category>Browser Security</category><category>Supply Chain</category><category>Malicious Extension</category></item><item><title>Chrome 149 Update Patches 18 High-Severity UAF Vulnerabilities</title><link>https://runtimerebel.com/blog/chrome-149-update-patches-18-high-severity-uaf-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-149-update-patches-18-high-severity-uaf-vulnerabilities</guid><description>Google releases Chrome 149 to address 18 severe vulnerabilities, including multiple use-after-free defects in Graphics, Dawn, and Mojo components.</description><pubDate>Thu, 25 Jun 2026 09:15:58 GMT</pubDate><category>Google Chrome</category><category>CVE-2024-11812</category><category>Use After Free</category><category>Browser Security</category><category>RCE</category></item><item><title>Malicious Chrome Wallpaper Extensions Distribute Adware</title><link>https://runtimerebel.com/blog/malicious-chrome-wallpaper-extensions-distribute-adware</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-chrome-wallpaper-extensions-distribute-adware</guid><description>Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts.</description><pubDate>Mon, 15 Jun 2026 14:21:57 GMT</pubDate><category>Chrome Extensions</category><category>Adware</category><category>PUP</category><category>Browser Security</category><category>Fake Traffic</category><category>Malicious Extensions</category></item><item><title>Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide</title><link>https://runtimerebel.com/blog/chrome-149-update-patches-28-vulnerabilities-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-149-update-patches-28-vulnerabilities-mitigation-guide</guid><description>Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.</description><pubDate>Fri, 12 Jun 2026 09:36:27 GMT</pubDate><category>Google Chrome</category><category>Chrome 149</category><category>Use After Free</category><category>Memory Corruption</category><category>Browser Security</category></item><item><title>Google Patches CVE-2026-11645: 5th Chrome Zero-Day Exploited in 2026</title><link>https://runtimerebel.com/blog/google-patches-cve-2026-11645-5th-chrome-zero-day-exploited-in-2026</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-patches-cve-2026-11645-5th-chrome-zero-day-exploited-in-2026</guid><description>Google addresses CVE-2026-11645, a critical zero-day vulnerability in Chrome being actively exploited. Learn about patch guidance and detection strategies.</description><pubDate>Tue, 09 Jun 2026 09:17:29 GMT</pubDate><category>CVE-2026-11645</category><category>Google Chrome</category><category>Zero-Day</category><category>Browser Security</category></item><item><title>2026 Verizon DBIR Analysis: Securing the Browser Against Phishing</title><link>https://runtimerebel.com/blog/2026-verizon-dbir-analysis-securing-the-browser-against-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/2026-verizon-dbir-analysis-securing-the-browser-against-phishing</guid><description>The 2026 Verizon DBIR identifies browser-layer security gaps as a primary threat vector, highlighting risks from phishing, shadow AI, and malicious extensions.</description><pubDate>Fri, 05 Jun 2026 16:56:11 GMT</pubDate><category>Verizon DBIR</category><category>Browser Security</category><category>Phishing</category><category>Credential Theft</category><category>Shadow AI</category></item><item><title>Brave Origin: Reducing Browser Attack Surface via Paid Minimalism</title><link>https://runtimerebel.com/blog/brave-origin-reducing-browser-attack-surface-via-paid-minimalism</link><guid isPermaLink="true">https://runtimerebel.com/blog/brave-origin-reducing-browser-attack-surface-via-paid-minimalism</guid><description>Brave Software launches Brave Origin, a subscription-based minimalist browser that removes AI, crypto, and VPN features to prioritize privacy and performance.</description><pubDate>Fri, 05 Jun 2026 01:00:35 GMT</pubDate><category>Brave Origin</category><category>Browser Security</category><category>Attack Surface Reduction</category><category>Privacy Tools</category><category>Chromium</category></item><item><title>Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript</title><link>https://runtimerebel.com/blog/chromium-rce-risk-unfixed-flaw-allows-background-javascript</link><guid isPermaLink="true">https://runtimerebel.com/blog/chromium-rce-risk-unfixed-flaw-allows-background-javascript</guid><description>Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.</description><pubDate>Thu, 21 May 2026 20:40:55 GMT</pubDate><category>Chromium</category><category>RCE</category><category>JavaScript</category><category>Browser Security</category><category>Google</category><category>Zero-Day</category></item><item><title>Microsoft Edge: Hardening Against Cleartext Password Exposure</title><link>https://runtimerebel.com/blog/microsoft-edge-hardening-against-cleartext-password-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-edge-hardening-against-cleartext-password-exposure</guid><description>Microsoft Edge will no longer load cleartext passwords into memory at startup, mitigating a significant local credential access risk for users.</description><pubDate>Fri, 15 May 2026 16:41:38 GMT</pubDate><category>Microsoft Edge</category><category>Browser Security</category><category>Cleartext Passwords</category><category>Credential Theft</category><category>Memory Security</category><category>Security Hardening</category></item><item><title>Bypassing Enterprise DLP via Browser-Based Data Exfiltration</title><link>https://runtimerebel.com/blog/bypassing-enterprise-dlp-via-browser-based-data-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-enterprise-dlp-via-browser-based-data-exfiltration</guid><description>Examine how modern SaaS workflows and generative AI prompts bypass traditional DLP, creating significant visibility gaps in enterprise security posture.</description><pubDate>Thu, 07 May 2026 16:41:43 GMT</pubDate><category>DLP</category><category>Data Exfiltration</category><category>SaaS Security</category><category>GenAI Risk</category><category>Browser Security</category></item><item><title>Microsoft Edge Cleartext Password Exposure Risks — Mitigation Guide</title><link>https://runtimerebel.com/blog/microsoft-edge-cleartext-password-exposure-risks-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-edge-cleartext-password-exposure-risks-mitigation-guide</guid><description>Critical analysis of Microsoft Edge credential storage risks. Learn how to prevent cleartext password extraction and secure browser-based identities.</description><pubDate>Tue, 05 May 2026 12:39:48 GMT</pubDate><category>Microsoft Edge</category><category>Credential Theft</category><category>Browser Security</category><category>Windows DPAPI</category></item><item><title>Firefox 150 Patch: 271 Zero-Days Found via Claude Mythos — Update Now</title><link>https://runtimerebel.com/blog/firefox-150-patch-271-zero-days-found-via-claude-mythos-update-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/firefox-150-patch-271-zero-days-found-via-claude-mythos-update-now</guid><description>Firefox 150 addresses 271 vulnerabilities discovered by Anthropic’s Claude Mythos AI model, highlighting a shift in automated vulnerability discovery.</description><pubDate>Wed, 29 Apr 2026 12:42:45 GMT</pubDate><category>Firefox</category><category>Anthropic</category><category>Claude Mythos</category><category>Mozilla</category><category>AI Security</category><category>Browser Security</category></item><item><title>Python Infostealer Targeting Browser Credentials and Discord Tokens</title><link>https://runtimerebel.com/blog/python-infostealer-targeting-browser-credentials-and-discord-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-infostealer-targeting-browser-credentials-and-discord-tokens</guid><description>Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.</description><pubDate>Tue, 21 Apr 2026 08:46:00 GMT</pubDate><category>Python Malware</category><category>Infostealer</category><category>Discord Webhooks</category><category>Credential Theft</category><category>Browser Security</category></item><item><title>Securing Enterprise Browser Environments Against AI Extension Risks</title><link>https://runtimerebel.com/blog/securing-enterprise-browser-environments-against-ai-extension-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-enterprise-browser-environments-against-ai-extension-risks</guid><description>Discover the security blind spots of AI browser extensions and how to mitigate data exfiltration risks in corporate environments via managed policies.</description><pubDate>Fri, 10 Apr 2026 12:25:18 GMT</pubDate><category>Browser Security</category><category>AI Threats</category><category>Shadow AI</category><category>Data Exfiltration</category><category>LayerX</category></item><item><title>Google Chrome Zero-Day Patch: Fourth In-the-Wild Exploit</title><link>https://runtimerebel.com/blog/google-chrome-zero-day-patch-fourth-in-the-wild-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-zero-day-patch-fourth-in-the-wild-exploit</guid><description>Google has released an urgent security update for Chrome, patching the fourth zero-day vulnerability actively exploited in 2024. Update now to protect against…</description><pubDate>Wed, 01 Apr 2026 12:27:55 GMT</pubDate><category>Chrome</category><category>Zero-Day</category><category>Browser Security</category><category>Google</category><category>Vulnerability</category><category>Exploitation</category></item><item><title>DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft</title><link>https://runtimerebel.com/blog/deepload-malware-leverages-clickfix-wmi-for-browser-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/deepload-malware-leverages-clickfix-wmi-for-browser-credential-theft</guid><description>DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.</description><pubDate>Mon, 30 Mar 2026 20:18:04 GMT</pubDate><category>DeepLoad</category><category>ClickFix</category><category>WMI</category><category>Credential Theft</category><category>Malware Loader</category><category>Browser Security</category><category>Social Engineering</category></item><item><title>Firefox 149 Integrated VPN: Analysis of Privacy and Security Features</title><link>https://runtimerebel.com/blog/firefox-149-integrated-vpn-analysis-of-privacy-and-security-features</link><guid isPermaLink="true">https://runtimerebel.com/blog/firefox-149-integrated-vpn-analysis-of-privacy-and-security-features</guid><description>Mozilla introduces a built-in VPN in Firefox 149 with a 50GB monthly data cap, enhancing user privacy while creating new visibility challenges for SOC teams.</description><pubDate>Tue, 24 Mar 2026 20:19:18 GMT</pubDate><category>Mozilla Firefox</category><category>Firefox 149</category><category>VPN</category><category>Browser Security</category><category>Privacy Tools</category></item><item><title>GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions</title><link>https://runtimerebel.com/blog/glassworm-malware-detecting-obfuscated-payloads-in-browser-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-detecting-obfuscated-payloads-in-browser-extensions</guid><description>Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.</description><pubDate>Tue, 17 Mar 2026 00:33:59 GMT</pubDate><category>GlassWorm</category><category>ChromeLoader</category><category>Browser Security</category><category>Javascript Obfuscation</category><category>Infostealer</category></item><item><title>Chrome Extensions QuickLens and BuildMelon Hijacked via Ownership Transfer</title><link>https://runtimerebel.com/blog/chrome-extensions-quicklens-and-buildmelon-hijacked-via-ownership-transfer</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-extensions-quicklens-and-buildmelon-hijacked-via-ownership-transfer</guid><description>Attackers are exploiting Chrome extension ownership transfers to weaponize QuickLens and BuildMelon tools for code injection and data harvesting.</description><pubDate>Mon, 09 Mar 2026 12:18:29 GMT</pubDate><category>Chrome Extension</category><category>Browser Security</category><category>Supply Chain Attack</category><category>QuickLens</category><category>BuildMelon</category><category>Data Theft</category></item><item><title>Firefox 148 Security Update: Anthropic AI Uncovers 22 Vulnerabilities</title><link>https://runtimerebel.com/blog/firefox-148-security-update-anthropic-ai-uncovers-22-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/firefox-148-security-update-anthropic-ai-uncovers-22-vulnerabilities</guid><description>Anthropic&apos;s Claude Opus 4.6 AI model identified 22 security vulnerabilities in Firefox, including 14 high-severity flaws addressed in the version 148 release.</description><pubDate>Sat, 07 Mar 2026 20:09:17 GMT</pubDate><category>Firefox</category><category>Anthropic</category><category>Claude Opus 4 6</category><category>Mozilla</category><category>Browser Security</category><category>AI Security</category></item><item><title>Enterprise Browser Security: Emerging Blind Spots &amp; AI Web Tool Risks</title><link>https://runtimerebel.com/blog/enterprise-browser-security-emerging-blind-spots-ai-web-tool-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/enterprise-browser-security-emerging-blind-spots-ai-web-tool-risks</guid><description>Keep Aware&apos;s 2026 report reveals critical enterprise browser security gaps, citing AI web tool use, phishing, and extensions as major blind spots for defenders.</description><pubDate>Thu, 05 Mar 2026 16:25:36 GMT</pubDate><category>Browser Security</category><category>Enterprise Security</category><category>Phishing</category><category>Malicious Extensions</category><category>AI Web Tools</category><category>Social Engineering</category><category>Keep Aware Report</category></item><item><title>Google Chrome Two-Week Release Cycle: Reducing the Patch Gap</title><link>https://runtimerebel.com/blog/google-chrome-two-week-release-cycle-reducing-the-patch-gap</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-two-week-release-cycle-reducing-the-patch-gap</guid><description>Google transitions Chrome to a two-week stable release cycle to accelerate security patching and minimize the window for n-day vulnerability exploitation.</description><pubDate>Tue, 03 Mar 2026 20:12:17 GMT</pubDate><category>Google Chrome</category><category>Patch Management</category><category>Chromium</category><category>Browser Security</category></item><item><title>CVE-2026-0628: Chrome Gemini Panel Exploit Enables Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-0628-chrome-gemini-panel-exploit-enables-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0628-chrome-gemini-panel-exploit-enables-privilege-escalation</guid><description>A high-severity flaw in Google Chrome&apos;s Gemini side panel allowed malicious extensions to bypass security policies and access local files on target systems.</description><pubDate>Mon, 02 Mar 2026 20:12:51 GMT</pubDate><category>CVE-2026-0628</category><category>Google Chrome</category><category>Privilege Escalation</category><category>Gemini</category><category>Browser Security</category></item></channel></rss>