CuraSec

tag: Browser-Security · 3 items

2026-08-03 · BleepingComputer · source ↗ #browser-security#chrome#extensions
  • Engineer — Plan: Review any policy-deployed Chrome extensions that control the New Tab page or default search engine before this change ships; audit enterprise extension policies to avoid unexpected breakage.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-16 · The Hacker News · source ↗ #browser-security#cve#patch
  • Engineer — Act: CVE-2026-15719 has a public PoC on GitHub and Mozilla acknowledges public exploit code exists; update Firefox to the patched release immediately across all managed endpoints and developer workstations.
  • SOC/IR — Plan: With public exploit code confirmed for Firefox WebAssembly and DOM navigation flaws, build or tune detections for browser exploitation patterns (unusual child processes, suspicious renderer crashes) and prepare to hunt if active exploitation is reported.
  • Leader — Skip
  • Signals: CVE-2026-15718 — CISA KEV: not listed, EPSS 0.00, no public PoC found · CVE-2026-15719 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
2026-07-12 · HN (cve) · source ↗ #browser-security#zero-day#cve
  • Engineer — Act: KEV-listed zero-day actively exploited in Chrome’s CSS engine; update Chrome/Chromium to the patched stable release immediately and verify managed browsers in your fleet are on the latest version.
  • SOC/IR — Act: Active in-the-wild exploitation means assume-breach posture for any endpoint running unpatched Chrome; hunt for suspicious child processes or unusual network connections from Chrome since the February 2026 stable release date, and check EDR telemetry for exploitation indicators.
  • Leader — Plan: CISA KEV listing confirms active exploitation of a Chrome browser zero-day; validate that your IT/engineering teams have a forced browser-update mechanism and confirm rollout completion — this is routine but warrants a status check given KEV designation.
  • Signals: CVE-2026-2441 — CISA KEV: listed, EPSS 0.22, public PoC on GitHub