Visualização normal

Antes de ontemSecurity Affairs
  • ✇Security Affairs
  • U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini
    U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046, an actively exploited V8 type confusion flaw.
     

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

4 de Setembro de 2026, 19:50

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog.

This week, Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046, an actively exploited V8 type confusion flaw.

The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page.

“CVE-2026-85046: Type confusion in V8.” reads the advisory. “Google is aware that an exploit for CVE-2026-85046 exists in the wild.”

As usual, Google did not disclose technical details about the attacks exploiting this vulnerability or attribute them to any specific threat actor.

Security researcher Salvatore Gulizia, known as Serotav, reported the flaw on August 4, 2026, and received a $1,000 bug bounty.

“a v8 bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arb r/w on the js heap.” wrote Serotav. “The bug was present in both maglev and turbofan.”

CVE-2026-85046 is the sixth actively exploited Chrome zero-day of 2026. Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:

  • February 2026 – CVE-2026-2441 (CVSS score: 8.8) – Use after free in CSS.
  • March 2026 – CVE-2026-3909 (CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and CVE-2026-3910 (CVSS score: 8.8) – Flaw in the implementation of the V8 JavaScript/WebAssembly engine.
  • April 2026 – CVE-2026-5281 (CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
  • June 2026 – CVE-2026-11645 (CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine

Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaw by September 18, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

  • ✇Security Affairs
  • Google fixes the sixth actively exploited Chrome zero-day of 2026 Pierluigi Paganini
    Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page. “CVE
     

Google fixes the sixth actively exploited Chrome zero-day of 2026

4 de Setembro de 2026, 05:24

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage.

Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw.

The bug affects Chrome’s JavaScript and WebAssembly engine and could let a remote attacker execute arbitrary code inside the browser sandbox by using a specially crafted HTML page.

“CVE-2026-85046: Type confusion in V8.” reads the advisory. “Google is aware that an exploit for CVE-2026-85046 exists in the wild.”

As usual, Google did not disclose technical details about the attacks exploiting this vulnerability or attribute them to any specific threat actor.

Security researcher Salvatore Gulizia, known as Serotav, reported the flaw on August 4, 2026, and received a $1,000 bug bounty.

“a v8 bug in the compilers that leads to an array containing PACKED_ELEMENTS to receive the map PACKED_SMI_ELEMENTS, this can be turned into arb r/w on the js heap.” wrote Serotav. “The bug was present in both maglev and turbofan.”

CVE-2026-85046 is the sixth actively exploited Chrome zero-day of 2026. Since the start of the year, Google has addressed the following zero-day flaws exploited in attacks in the wild:

  • February 2026 – CVE-2026-2441 (CVSS score: 8.8) – Use after free in CSS.
  • March 2026 – CVE-2026-3909 (CVSS score: 8.8) – Out-of-bounds write in the Skia 2D graphics library and CVE-2026-3910 (CVSS score: 8.8) – Flaw in the implementation of the V8 JavaScript/WebAssembly engine.
  • April 2026 – CVE-2026-5281 (CVSS score: 8.8) – Use-after-free bug in Dawn, the WebGPU component used for graphics processing.
  • June 2026 – CVE-2026-11645 (CVSS score: 8.8) – Out-of-bounds memory access in the V8 JavaScript engine

Google has updated Chrome Stable to version 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, with the rollout happening over the coming days and weeks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Chrome)

  • ✇Security Affairs
  • Google AI Supercharges Chrome Security, Fixing 1,072 Bugs Pierluigi Paganini
    Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team fixed 1,072 security bugs, more than the total fixed across the prior 23 milestones combined. That’s not a marginal improv
     

Google AI Supercharges Chrome Security, Fixing 1,072 Bugs

31 de Julho de 2026, 10:46

Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching

Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team fixed 1,072 security bugs, more than the total fixed across the prior 23 milestones combined. That’s not a marginal improvement. That’s a different category of operation.

“In early 2026, we built an agent harness that used Gemini to find vulnerabilities across the broader Chrome codebase with higher efficiency and lower false positives. One of the bugs we found was a sandbox escape that would allow a compromised renderer to trick the browser into reading local files — a bug that quietly survived in our codebase for more than 13 years!” states Google. “For many of us, this moment cemented the potential of AI-powered vulnerability detection.”

The same tools that find bugs are now also triaging them. Historically, triaging a single security report took between 5 and 30 minutes of human time. The automated system now handles filtering duplicates, reproducing the bug, assigning severity, and routing it to the right team — the Chrome team estimates this is saving hundreds of hours of developer time per month.

Fixing bugs at scale required rethinking the entire repair pipeline. The current approach runs a fixing agent that produces multiple candidate patches, a separate critic agent that evaluates which is best, and a test-writing agent that verifies the fix works across all Chrome platforms before a human ever reviews it.

“We have partnered closely with Google DeepMind and Project Zero for years, including on BigSleep and CodeMender. These tools are natively integrated into our continuous integration (CI) system, running every 24 hours across all CLs to proactively detect security bugs.” continues the IT giant. “This integration has yielded significant results: in May alone, we blocked over 20 vulnerabilities from reaching production, including a critical S1+ issue.”

The external vulnerability reward program also saw a sharp increase: by March 2026, Chrome received more bug reports than it had in all of 2025, which prompted a change to the VRP to focus researchers on findings that add something beyond what internal AI tools are already catching.

The speed at which fixes reach users matters as much as the speed at which bugs are found.

“Once a fix has landed and is visible in the public open source codebase, attackers can start to reverse engineer and exploit the bug before the fix reaches users’ machines — so called “N-day” attacks.” states Google. “This is commonly referred to as the “patch gap.” Since fixes committed to the main “tree” typically take weeks to reach the Chrome Stable channel (what the vast majority of our users run), minimizing this patch gap is a critical part of our strategy.”

Even that cadence isn’t enough if users don’t restart their browser to apply the update, which most people delay for understandable reasons. Chrome is now working on dynamic patching that replaces background processes on the fly without requiring a full restart, and has already shipped a change in Chrome 150 that automatically restarts the browser on macOS when all windows are closed and an update is pending.

The longer-term structural work is about eliminating entire bug categories rather than patching individual instances. Chrome is expanding MiraclePtr, a technology that neutralizes use-after-free vulnerabilities, to more libraries including Skia, ANGLE, and Dawn, with a goal of covering up to 90% of UAF bugs on the GPU main thread. A separate “spanification” effort has already brought 97% of first-party Chrome code to compile cleanly with strict unsafe-buffer warnings — pushing spatial safety enforcement into the compiler rather than relying on runtime checks. The honest admission in the post is that runtime mitigations have a ceiling, and the long-term answer is rewriting high-risk components in Rust. Chrome is building a centralized Rust SDK to make that a routine engineering choice rather than a heroic one.

The scale of the dependency problem is worth stating plainly. Chrome has more than 2,300 third-party dependencies across Chromium and satellite projects, about 1,700 of which ship to users in products ranging from Android devices to cloud enterprise stacks. All of those are now being moved onto automated update pipelines that roll them to their latest upstream versions continuously, with safety signals from Google’s Open Source Security Intelligence Platform providing guardrails against introducing new problems in the process.

“The AI era has undeniably intensified the software security threat landscape, but by combining rapid deployment mechanisms with deep structural defenses, we are ensuring the advantage remains firmly with defenders. With this, Chrome and the broader web become safer with every update.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)

  • ✇Security Affairs
  • Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft Pierluigi Paganini
    Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage. Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-controlled webpage to silently steal a visitor’s WhatsApp chats, contacts, profile name, and message previews in plain text. The extension sits on roughly 329 million browsers. No malware, no phis
     

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

22 de Julho de 2026, 18:19

Adobe patched CVE-2026-48294, a flaw in Adobe Acrobat Chrome extension that could let attackers steal WhatsApp Web chats by luring users to a webpage.

Guardio Labs researcher Shaked Biner disclosed HermeticReader, a vulnerability chain in the Adobe Acrobat Chrome extension that allowed any attacker-controlled webpage to silently steal a visitor’s WhatsApp chats, contacts, profile name, and message previews in plain text. The extension sits on roughly 329 million browsers. No malware, no phished password, no compromised session cookie — just visiting the wrong page was enough.

“Read the prerequisites list of this exploit chain and the discomfort sets in: no malware is installed, no password is phished, no session cookie is touched. There is no zero-day in WhatsApp.” reads the report published by Guardio Labs. “The attacker needs no Adobe account and no foothold on the machine. Only for the victim to visit a simple attacker-controlled static page.”

The attack chains three separate flaws in the extension’s internal messaging system. None of them are dramatic on their own. Together they hand an attacker full DOM control over an open WhatsApp Web tab.

The first flaw is that the extension’s web-accessible resource pages, frame.html, searchWidget.html, and others, can be embedded as hidden iframes by any website. Those pages parse a JSON blob directly from their URL query string and relay it to the extension’s service worker as a message.

“Because that script runs inside chrome-extension://efaidn…/, the service worker sees its message as coming from a trusted internal source. The extension’s own identity becomes the attacker’s mask. The page can set any fields on the message , typekeyvalue, anything else.” continues the report. “Two fields are not free: panel_op has to be set to "load-frictionless" so that frame.js takes the relay code path at all, and main_op is overwritten to "relay_to_content" on the way out.”

The service worker’s message listener never checks the sender. Its storage writer has no allowlist on what can be written. Any page can write any key into the extension’s local storage in zero clicks.

That storage write matters because of the third flaw: Adobe’s Hermes engine, the component that handles WhatsApp Web integration, activates based on a feature flag read from local storage. Write the right key – floodgate-add = "dc-cv-hermes" – and Hermes arms immediately. With Hermes running, the attacker controls a command dispatcher inside WhatsApp’s tab that can inject HTML, invoke methods on any DOM node, submit forms, and relay messages back to the service worker. One of those commands, APPEND_HTML_TO_TARGET, can replace WhatsApp’s login QR code with an attacker-controlled one, meaning anyone who scans it to link a new device pairs the attacker’s session instead.

The data exfiltration technique is what makes the research genuinely clever.

“We never asked the extension to read anything. We asked WhatsApp to submit itself to us – and it did.” states the report.

The attack injects a POST form into WhatsApp’s DOM, then uses the ELEMENT_OPERATION command to physically move WhatsApp’s entire body node into the form’s option element. Because an option element with no value attribute submits its text content, and because WhatsApp’s content security policy contains no form-action directive, submitting the form sends the entire rendered page, chat list, contact names, message text, to the attacker’s server. WhatsApp does the exfiltration itself.

Guardio found this within hours of Adobe shipping version 26.5.2.1 on June 3, using a custom agentic AI system that unpacked and analyzed the extension’s 344 obfuscated JavaScript files, mapped code diffs against previously analyzed flows, and worked through a 138-case service-worker message dispatcher.

“The Agentic AI Research harness is not only a clever and innovative way to research – it already became mandatory! From a new version release trigger, the work is shared: The agent unpacks the bundle, beautifies 344 obfuscated JavaScript files, finds the code diffs and maps them against already mapped and analyzed flows, continues to map a 138-case service-worker message dispatcher, and so much more.” states Guardio Labs. “At this time, we’ve steered the analysis toward what is actually reachable and worth proving, cleared dead ends, and presented plausible ideas and attack vectors to pursue. That combination is what collapsed the time line into hours instead of days, weeks or even months.”

Adobe’s response matched the speed: acknowledged, patched, and shipped within the same weekend the report arrived. CVE-2026-48294 was issued days later.

The structural lesson here isn’t about any single clever trick. Twelve individually unremarkable shortcuts in message passing, storage handling, feature flags, and host matching composed into a chain that reached 329 million browsers. The era in which a high-install extension could rely on nobody looking at the plumbing closely is ending, for defenders and attackers alike.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Adobe Acrobat)

❌
❌