Security researchers identified six malicious Chrome extensions with cybersecurity badness scores between 89-97, including Tik Tok Downloader (97/100), Cat in Autumn Live Wallpaper (94/100), and 1Inch Defi Portfolio (94/100). The extensions pose significant malware threats to browser users.
Multiple anime-themed Chrome extensions have been flagged as malicious with high cybersecurity badness scores (85–99 out of 100), including Vinland Saga, Blue Lock, Ben 10, Jujutsu Kaisen, and Pokémon wallpaper extensions. Security researchers warn users against installing these compromised browser plugins.
Google released Chrome 153 on September 9, 2026, fixing at least 12 vulnerabilities including CVE-2026-87491, an out-of-bounds bug in V8 that was actively exploited in the wild. This marked the seventh actively exploited Chrome zero-day patched in 2026.
On 4 September 2026, BSI (German federal cybersecurity agency) disclosed multiple vulnerabilities across SEPPmail, Kibana, Google Chrome, Microsoft Cloud services, and the vm2 JavaScript sandbox. vm2 rated critical for remote code execution; others rated high. No active exploitation was reported.
Cybersecurity researchers disclosed PEEP on September 7, 2026, a sophisticated post-exploitation toolkit that poses as a browser-bookmarks extension and can turn Chrome and Edge profiles into persistent host command-execution backdoors. The malware requires prior administrative access but enables attackers to maintain control after initial compromise.
Between 27 and 30 July 2026, technology and security professionals shared updates on virtualization (UTM Triton driver for QEMU), satellite technology (Amazon Leo direct-to-device vision), kernel vulnerabilities (Fraggap Linux CVE-2026-53362), law enforcement actions (FSB arrest warrant for Pavel Durov), browser security (Chrome 151 patches 370 vulnerabilities), and real-time system attacks (NosyNeighbor). The reports span infrastructure, security, and compliance domains.