Skip to main content

Tag: chromium based browsers

4 articles

Laptop on cluttered desk with browser extension icon on screen, surrounded by papers and cityscape view through window.

Malicious Extensions Exploit AI Browser Agents

Imagine a single malicious browser extension handing an AI-powered browser agent a set of instructions, allowing it to act with the browser's existing privileges - and putting your entire online presence at risk. Security researcher Gal Weizman has uncovered this vulnerability with his proof-of-concept, BragJack, which can hijack AI assistants embedded in popular Chromium-based browsers.

Analyst 207
Blurred computer screen at a corporate office workstation in bright daylight.

ToddyCat APT Group Exploits Google API for Email Access

Meet ToddyCat, a sneaky APT group that's taken automation to the next level with its new tool, Umbrij - allowing it to secretly tap into corporate email and cloud resources by exploiting Google API. This stealthy move has helped ToddyCat remain undetected by monitoring systems, leaving organizations vulnerable to attack.

Analyst 207
City transit platform with people in background and laptop on blurred table in foreground.

Gremlin Stealer Evolves with Advanced Evasion Tactics

In just 12 months, the Gremlin stealer malware has transformed from a basic credential harvester to a sophisticated modular toolkit that can stealthily siphon sensitive information from compromised systems. Its latest variant now specifically targets Chromium-based browsers, making it an even more formidable threat.

Analyst 207
Laptop screen displays browser password manager in bright, neutral setting.

Microsoft Edge Exposes Saved Passwords in Plaintext

Microsoft Edge's password management has a concerning vulnerability: it loads all saved passwords into browser memory in plaintext at startup, making it easier for hackers to steal credentials on compromised systems. This is in stark contrast to other Chromium-based browsers like Google Chrome and Brave, which only decrypt passwords when needed.

Analyst 207