Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
The browser update resolves several critical-severity memory safety and memory corruption flaws.
The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday.
The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.
The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565βs campaigns differed from those attacks by using multiple fake websites to deceive victims.
Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.
While UTA0565 showcased a variance in tactics, it used the same components researchers observed in previous instances of the exploit kit across multiple Chinese threat groups.
βThis seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups,β Volexity wrote in the blog post. βThe activity reported so far reflects only two organizationsβ observations; the full scope and impact are likely far broader.β
The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Sept. 8 in Windows Advanced Local Procedure Call.Β
Proofpoint, which previously observed multiple state-aligned threat groups chaining the vulnerabilities together in attacks since last August, said a limited group of organizations were exposed to all three vulnerabilities in a short window.Β
Proofpoint previously attributed attacks involving the zero-days to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. At the time it warned that attackers of other origins and motivations could strike soon as well.
Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as βCLEANGULP.β Researchers also found several domains likely used by UTA0565 in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations.Β
βUTA0565βs use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,β researchers wrote. βUsing real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.β
The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop.
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.
The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
Proofpoint researchers have spotted at least four state-aligned threat groups chain a trio of zero-day vulnerabilities to conduct espionage on various targets of interest to Chinaβs government since late August.Β
The Chinese espionage group that Proofpoint tracks as TA412, also known as Violet Typhoon and APT31, struck first, exploiting the chain of vulnerabilities Aug. 28. At least three additional espionage threat groups followed suit, exploiting the same vulnerabilities in subsequent waves of attacks days later, researchers said.
The exploit chain Proofpoint calls BlueMoon targets Chrome, Chromium-based browsers and Microsoft Windows. It allows attackers to run code in the browserβs sandbox, escape the sandbox and gain system privileges to access a targeted machine, said Mark Kelly, staff threat researcher at Proofpoint.
βAll three vulnerabilities were exploited before patches were available to the public,β he said.
The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Tuesday in Windows Advanced Local Procedure Call.Β
βWhile the V8 vulnerabilities were known and fixed in Chromium source code, they were not yet patched in the latest publicly available browsers at the time of the activity, meaning they effectively functioned as zero-days in those products,β Kelly said.
Proofpoint said the exploit kit developer likely reverse engineered the publicly available Chromium patches to weaponize the browser exploit chain during that gap.
With a limited group of organizations exposed to all three vulnerabilities, attackers moved quickly and likely rushed development to target a narrow pool of potential targets. βIn all observed cases, the infrastructure used for exploit delivery was created on the same day as β or in the days immediately preceding β the associated campaigns,β Proofpoint wrote in a threat intelligence report.
APT31, a group thatβs committed espionage on behalf of Chinaβs Ministry of State Security, including seven Chinese nationals indicted by the Justice Department in 2024, dropped various lures containing the exploit chain loader in phishing emails targeting non-governmental organizations, mining companies and commodity trading firms in the United States.Β
The phishing link installed a malicious browser extension disguised as Google Gemini on targeted machines, enabling attackers to surveil browser activity, steal credentials and execute commands, according to Proofpoint.Β
Other distinct threat groups have also used the BlueMoon exploit chain with some slight technical changes and variances in targeting.Β
βProofpoint observed BlueMoon usage as recently as Sept. 8,β Kelly said. βThe activity peaked Sept. 2-3 immediately prior to the Chrome patch being released and has continued intermittently since then.β
A China-aligned espionage threat group Proofpoint tracks as UNK_LateNight targeted multiple U.S. aerospace companies Sept. 2. Researchers also that day observed UNK_DoubleCheck, a suspected espionage-motivated threat group targeting Vietnamese manufacturing organizations with emails from a compromised Southeast Asian government account.Β
Researchers said UNK_QuietRacket, another espionage group aligned with China, targeted government, consulting and financial sector organizations in Indonesia and Singapore Sept. 3.
Proofpoint has directly observed fewer than 20 organizations targeted globally thus far, but Kelly said the true number of impacted organizations is likely much higher.Β
While Proofpoint attributes most of the observed attacks to Chinese espionage groups, attackers of other origins and motivations could strike soon as well.Β
βGiven its ease of adoption, we expect the exploit kit is likely to proliferate further and be adopted by additional espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers,β Kelly said.
The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop.
Googleβs Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine.
The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek.
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.
The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.
The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure.
The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device ownerβs private information, according to researchers.
Certo Software said in a blog post Tuesday that stalkers are making use of Chromeβs sync capability β meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too β to spy on a phone ownerβs browsing history and gain access to their stored passwords.
As an illustration, Certo used the case of a pseudonymous victim, Emma, who had searched for a family lawyer and visited a domestic violence support website while her partner was sleeping, only for him to bring up to her two days later.
βEmma had been careful to only ever use her own device, and she hadnβt noticed any new apps appear on her phone,β wrote Certo co-founder Russell Kent-Payne. βWhat she didnβt know was that weeks earlier, during a few unattended minutes with her phone, he had opened the Chrome app and quietly signed it into a Google account of his own. From that moment on, every site she visited was being copied straight to his account, viewable from any device, anywhere in the world.β
The surveillance is as easy as that: brief access to a phone, signing into a Google account and making sure sync is turned on for that account.
Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said on the Bluesky social media app that Certoβs research serves as βan important reminder that tech-enabled abuse isnβt just limited to stalkerware.β
Certo said that Google could do a couple things, such as providing a temporary notification whenever a new account is added or sync is turned on or offering a regular marker to indicate when sync is active and which account itβs syncing to, to protect users.
Google did not respond to multiple requests for comment about Certoβs findings.
But the uptick in usage of that stalking method could be a byproduct of security successes elsewhere in the fight against spyware, Certo said.
βModern smartphones are harder to compromise than ever. Regular security updates, stricter app store rules, and on-device threat detection have made traditional spyware a much riskier bet for a cyberstalker than it used to be,β Kent-Payne wrote. βAs a result, weβre increasingly seeing abusers turn to something far simpler: the legitimate apps already sitting on their victimβs phone. No installation, no suspicious permissions, no telltale battery drain β just a quiet misuse of a feature the victim never knew existed.β
At the same time, Chrome is the worldβs most popular browser, and this isnβt the first time security concerns have popped up about its sync feature, among other worries.
The post Security researchers find stalkers abusing Chromeβs sync feature appeared first on CyberScoop.
Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed βBlueHammer.β Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe Reader nixes an actively exploited flaw that can lead to remote code execution.
![]()
Redmond warns that attackers are already targeting CVE-2026-32201, a vulnerability in Microsoft SharePoint Server that allows attackers to spoof trusted content or interfaces over a network.
Mike Walters, president and co-founder of Action1, said CVE-2026-32201 can be used to deceive employees, partners, or customers by presenting falsified information within trusted SharePoint environments.
βThis CVE can enable phishing attacks, unauthorized data manipulation, or social engineering campaigns that lead to further compromise,β Walters said. βThe presence of active exploitation significantly increases organizational risk.β
Microsoft also addressed BlueHammer (CVE-2026-33825), a privilege escalation bug in Windows Defender. According to BleepingComputer, the researcher who discovered the flaw published exploit code for it after notifying Microsoft and growing exasperated with their response. Will Dormann, senior principal vulnerability analyst at Tharros, says he confirmed that the public BlueHammer exploit code no longer works after installing todayβs patches.
Satnam Narang, senior staff research engineer at Tenable, said April marks the second-biggest Patch Tuesday ever for Microsoft. Narang also said there are indications that a zero-day flaw Adobe patched in an emergency update on April 11 β CVE-2026-34621 β has seen active exploitation since at least November 2025.
Adam Barnett, lead software engineer at Rapid7, called the patch total from Microsoft today βa new record in that categoryβ because it includes nearly 60 browser vulnerabilities. Barnett said it might be tempting to imagine that this sudden spike was tied to the buzz around the announcement a week ago today of Project Glasswing β a much-hyped but still unreleased new AI capability from Anthropic that is reportedly quite good at finding bugs in a vast array of software.
But he notes that Microsoft Edge is based on the Chromium engine, and the Chromium maintainers acknowledge a wide range of researchers for the vulnerabilities which Microsoft republished last Friday.
βA safe conclusion is that this increase in volume is driven by ever-expanding AI capabilities,β Barnett said. βWe should expect to see further increases in vulnerability reporting volume as the impact of AI models extend further, both in terms of capability and availability.β
Finally, no matter what browser you use to surf the web, itβs important to completely close out and restart the browser periodically. This is really easy to put off (especially if you have a bajillion tabs open at any time) but itβs the only way to ensure that any available updates get installed. For example, a Google Chrome update released earlier this month fixed 21 security holes, including the high-severity zero-day flaw CVE-2026-5281.
For a clickable, per-patch breakdown, check out the SANS Internet Storm Center Patch Tuesday roundup. Running into problems applying any of these updates? Leave a note about it in the comments below and thereβs a decent chance someone here will pipe in with a solution.



![]()
Brian King // News from Google this week says that Chrome will start enforcing Certificate Transparency a year from now. https://groups.google.com/a/chromium.org/forum/#!topic/ct-policy/78N3SMcqUGw This means that when Chrome contacts a website, if [β¦]
The post Certificate Transparency Means What, Again? appeared first on Black Hills Information Security, Inc..