Browser
Vulnerabilities and exploitation across Chrome, Firefox, Safari, Edge, and their smaller relatives — plus the browser-extension ecosystem, where a signed add-on can silently exfiltrate anything the browser can see.

Belgium eID Browser Extension Bugs Enable RCE
Severe vulnerabilities in Belgium's eID browser extension fully compromised the country's national identity trust framework, researchers confirmed, opening citizen accounts to remote code execution.

737 Fake Chrome VPN Extensions Route Traffic via Proxies
737 Chrome extensions impersonated VPN services while routing users' traffic through a single SOCKS5 proxy. Over 75,000 installs affected across the Store.

AI Finds 1,442 Chrome Bugs in Three Recent Releases
Google patched 1,442 security flaws across Chrome 149, 150, and 151 — more than the prior 23 releases combined. AI-assisted testing drove the surge.

JS Malvertising Assembles Malware in Browser Memory
Fake Solana, Luno, and TradingView sites run malicious JavaScript that builds malware in browser memory — no file written, standard AV misses it.

Claude for Chrome flaw lets other extensions read Gmail
Manifold says the trust-boundary flaw behind ClaudeBleed is still open in Claude for Chrome v1.0.80 — eight releases after Anthropic's May fix.

KU Leuven: 85 wallet extensions leak addresses cross-site
KU Leuven's DistriNet tested 85 Chrome crypto wallet extensions with ~35M installs. 17 link separate addresses in a single request. 22 of 36 ignore site disconnects.

ModHeader carried a dormant collector to 1.6M installs
Stripe OLT found a browsing-history collector inside the store-signed ModHeader extension. Edge pulled it July 3; Chrome pulled it July 10. The allow-list shipped empty.

Opera GX Patches Auto-Install Mods Flaw
Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.