browser-security

7 articles
sort: new top best
clear filter
0 3/10

Google released emergency Chrome patches for two actively exploited zero-days: CVE-2026-3909 (out-of-bounds write in Skia graphics library) and CVE-2026-3910 (inappropriate implementation in V8 JavaScript engine). Both vulnerabilities are being actively exploited in the wild, marking Chrome's third zero-day under attack in 2026.

CVE-2026-3909 CVE-2026-3910 CVE-2026-2441 Google Chrome Skia V8
theregister.com · Brajeshwar · 8 hours ago · details · hn
0 3/10

Google released patches for two high-severity zero-day vulnerabilities in Chrome affecting the Skia graphics library and V8 engine that were actively exploited in the wild. CVE-2026-3909 is an out-of-bounds write in Skia with CVSS 8.8 triggered via crafted HTML.

CVE-2026-3909 Google Chrome Skia V8
thehackernews.com · [email protected] (The Hacker News) · 11 hours ago · details
0 3/10

Google released emergency patches for two actively exploited Chrome zero-days: CVE-2026-3909 (out-of-bounds write in Skia graphics library enabling code execution) and CVE-2026-3910 (inappropriate V8 JavaScript engine implementation). Both vulnerabilities were discovered and patched by Google within two days of discovery.

CVE-2026-3909 CVE-2026-3910 CVE-2026-2441 Google Skia V8 Chrome Google Threat Analysis Group BleepingComputer
bleepingcomputer.com · Sergiu Gatlan · 13 hours ago · details
0 2/10

This opinion piece critiques Brave's decision to enable Media Router (Casting) by default on desktop without explicit user consent, arguing that automatic device discovery via SSDP/UPnP expands attack surface and contradicts the browser's privacy-first branding.

Brave Chrome Media Router SSDP UPnP
noguff · 16 hours ago · details · hn
0 6/10

A CORS misconfiguration in Twitter's niche platform allowed attackers to bypass origin validation by leveraging subdomain prefix matching (niche.co.evil.net) to steal private user data including images, emails, and CSRF tokens synced from Facebook, Instagram, and Twitter. The vulnerability was exploited via a simple JavaScript POC that exfiltrated sensitive information when visited by logged-in users.

Twitter Facebook Instagram niche (Twitter product) Rohan Aggarwal HackerOne Burp Suite
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A CORS misconfiguration vulnerability where the server's origin validation logic uses flawed regex/string matching that accepts malformed origin headers (e.g., 'private1com' instead of 'private.com'), allowing an attacker to register a lookalike domain and exfiltrate credentials and private information via a crafted CORS-enabled request.

Virus0X01 offensive hunterr
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 4/10
bug-bounty

A researcher documents discovering multiple MIME sniffing-dependent XSS vulnerabilities at Google by exploiting improper Content-Type headers and missing X-Content-Type-Options: nosniff headers, earning thousands in bounties while exploring how browsers may interpret non-HTML content as executable code.

Google KomodoSec
komodosec.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details