<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>cybercrime.club</title><link>https://cybercrime.club/tags/browser-security/</link><description>Infrastructure security news for people who build infrastructure.</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 09 Apr 2026 18:09:33 -0400</lastBuildDate><atom:link href="https://cybercrime.club/tags/browser-security/" rel="self" type="application/rss+xml"/><item><title>Chrome 147 Patches 60 Security Flaws Including Two Critical WebML RCE Bugs</title><link>https://cybercrime.club/posts/chrome-147-critical-webml-cve-2026-5858-5859-arbitrary-code-execution/</link><pubDate>Thu, 09 Apr 2026 18:09:33 -0400</pubDate><guid>https://cybercrime.club/posts/chrome-147-critical-webml-cve-2026-5858-5859-arbitrary-code-execution/</guid><description>Google ships Chrome 147.0.7727.55 with fixes for 60 vulnerabilities—two critical heap buffer overflow and integer overflow flaws in the WebML component enable remote code execution via crafted HTML pages.</description><category>vulnerabilities</category></item><item><title>Chrome Zero-Day CVE-2026-5281: WebGPU Use-After-Free Under Active Exploitation</title><link>https://cybercrime.club/posts/chrome-zero-day-cve-2026-5281-webgpu-dawn/</link><pubDate>Wed, 01 Apr 2026 10:13:00 -0400</pubDate><guid>https://cybercrime.club/posts/chrome-zero-day-cve-2026-5281-webgpu-dawn/</guid><description>Google patches fourth Chrome zero-day of 2026 — a use-after-free in the Dawn WebGPU implementation that enables arbitrary code execution via crafted HTML pages.</description><category>vulnerabilities</category></item><item><title>Three Chrome Zero-Days Patched in March Alone — What's Driving the Surge</title><link>https://cybercrime.club/posts/chrome-three-zero-days-march-2026/</link><pubDate>Sat, 28 Mar 2026 16:00:00 -0400</pubDate><guid>https://cybercrime.club/posts/chrome-three-zero-days-march-2026/</guid><description>Google patched three actively exploited Chrome zero-days this month. The browser attack surface is expanding faster than it's being hardened.</description><category>analysis</category></item></channel></rss>