Browser
Vulnerabilities and exploitation across Chrome, Firefox, Safari, Edge, and their smaller relatives — plus the browser-extension ecosystem, where a signed add-on can silently exfiltrate anything the browser can see.

Claude for Chrome flaw lets other extensions read Gmail
Manifold says the trust-boundary flaw behind ClaudeBleed is still open in Claude for Chrome v1.0.80 — eight releases after Anthropic's May fix.

KU Leuven: 85 wallet extensions leak addresses cross-site
KU Leuven's DistriNet tested 85 Chrome crypto wallet extensions with ~35M installs. 17 link separate addresses in a single request. 22 of 36 ignore site disconnects.

ModHeader carried a dormant collector to 1.6M installs
Stripe OLT found a browsing-history collector inside the store-signed ModHeader extension. Edge pulled it July 3; Chrome pulled it July 10. The allow-list shipped empty.

Opera GX Patches Auto-Install Mods Flaw
Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.