Vendor
Browser
Vulnerabilities and exploitation across Chrome, Firefox, Safari, Edge, and their smaller relatives — plus the browser-extension ecosystem, where a signed add-on can silently exfiltrate anything the browser can see.
Articles

● Breaking
browser
ModHeader carried a dormant collector to 1.6M installs
Stripe OLT found a browsing-history collector inside the store-signed ModHeader extension. Edge pulled it July 3; Chrome pulled it July 10. The allow-list shipped empty.
read →

browser
Opera GX Patches Auto-Install Mods Flaw
Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.
read →