Google Chrome data leakage bug confirmed as actively exploited – Go Health Pro

Google Chrome data leakage bug confirmed as actively exploited – Go Health Pro

A Google Chrome vulnerability allowing the leak of OAuth codes was added to the Known Exploited Vulnerabilities catalog by the Cybersecurity & Infrastructure Security Agency (CISA) on Thursday.The flaw, tracked as CVE-2025-4664, is due to insufficient policy enforcement in the Google Chrome Loader, Google said Wednesday.The vulnerability was discovered by security researcher Vsevolod Kokorin, who … Read more

Firefox patches flaw similar to exploited Chrome zero-day – Go Health Pro

Firefox patches flaw similar to exploited Chrome zero-day – Go Health Pro

Mozilla patched a Firefox browser vulnerability that was discovered after a similar Google Chrome flaw was found to be actively exploited in potential espionage campaigns.The critical flaw, tracked as CVE-2025-2857, could enable an attacker to escape the Firefox browser’s sandbox protection on Windows machines due to an error in the browser’s inter-process communication (IPC) code, … Read more

Popular AI tools tricked to create malware for Chrome browser – Go Health Pro

Popular AI tools tricked to create malware for Chrome browser – Go Health Pro

Cato Networks demonstrated how a threat intelligence researcher with no prior malware coding experience was able to trick popular large language model (LLM) tools to develop a Google Chrome infostealer.The news from earlier this week caught the eye of security pros, mainly because they were able to jailbrake LLMs like DeepSeek, Microsoft Copilot, and OpenAI’s … Read more

Here’s how hucksters are manipulating Google to promote shady Chrome extensions – Go Health Pro

Here’s how hucksters are manipulating Google to promote shady Chrome extensions – Go Health Pro

The people overseeing the security of Google’s Chrome browser explicitly forbid third-party extension developers from trying to manipulate how the browser extensions they submit are presented in the Chrome Web Store. The policy specifically calls out search-manipulating techniques such as listing multiple extensions that provide the same experience or plastering extension descriptions with loosely related … Read more

Chrome extensions compromised in Christmas Day supply chain attack – Go Health Pro

Chrome extensions compromised in Christmas Day supply chain attack – Go Health Pro

In a supply chain attack that was first detected on Dec. 25, several Chrome extensions were compromised after a Cyberhaven employee was tricked by a phishing email that stole the worker’s credentials to the Google Chrome Web Store. A Dec. 27 blog post by Cyberhaven explained the attacker used these credentials on Dec. 24 to … Read more