Skip to content
Threat Feed

Tag

Browser-Security

10 briefs RSS
medium advisory

Credential Access via Chromium Remote Debugging

Adversaries can exploit Chromium-based browser remote debugging features to extract authentication cookies and hijack active web sessions.

Chrome +1 credential-access information-stealer browser-security
1r 1t
high advisory

Chromium V8 Engine Out-of-Bounds Memory Access Vulnerability

CVE-2026-0899 is an out-of-bounds memory access vulnerability in the Chromium V8 JavaScript engine that may result in memory corruption, process crashes, or arbitrary code execution.

Chromium vulnerability browser-security
1c
high advisory

Phishing Campaign Leveraging Blob URLs and Microsoft Teams Redirects

Threat actors are using legitimate Microsoft Teams redirects to chain external resources and generate dynamic, browser-resident phishing pages via blob URLs to bypass static URL scanning.

Microsoft Teams phishing browser-security credential-theft microsoft-teams
2t 1i
medium advisory

Detection of Browser-Spawned Unix Shells with External Connectivity

Anomalous execution pattern where Unix-based browser processes spawn shells to initiate outbound external network connections, a TTP indicative of potential drive-by exploitation or browser-based post-exploitation.

execution browser-security linux macos endpoint cisco-nvm
1t
high advisory

Entra ID PRT Extraction via BrowserCore.exe Abuse

Adversaries are abusing the legitimate BrowserCore.exe component to perform unauthorized extraction of Entra ID Primary Refresh Tokens (PRTs) by invoking the binary outside of expected browser-managed contexts.

Microsoft Edge +1 credential-access browser-security windows session-hijacking
1r 2t
critical threat

Active Exploitation of Google Chromium V8 Type Confusion Vulnerability

A type confusion vulnerability in the Google Chromium V8 engine is being actively exploited in the wild, allowing remote attackers to achieve arbitrary code execution within the sandbox environment via crafted HTML pages.

exploited Chromium V8 +8 vulnerability chromium browser-security
1t 2c updated
high advisory

Chrome VPN Extension Persistence via Registry Modification

Adversaries can gain persistence or bypass network controls by installing unauthorized Chrome VPN extensions through the Windows Registry.

persistence browser-security windows
1r 1t
critical advisory

Multiple Vulnerabilities in Google Chrome and Microsoft Edge

Multiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.

Chrome +9 vulnerability browser-security patch-management
1t 2c updated
high threat

Jewelbug APT Dual-Purpose Espionage and Fraud Operations

Jewelbug, a China-linked mercenary APT, uses a custom C2 platform called XG-Web to conduct both state-sponsored espionage and large-scale cryptocurrency theft using custom backdoors and malicious browser extensions.

Jewelbug apt espionage credential-theft malware china middle-east southeast-asia browser-security
3t
high advisory

Pass-ta-key Attacks Targeting Google Chrome Passkey Implementation

Researchers identified multiple techniques allowing malware on Windows hosts to hijack Google-synced passkeys by extracting cryptographic material and forging authentication assertions.

Chrome passkey credential-access browser-security identity
1t