RC RANDOM CHAOS

browser security

8 posts

Your browser obeys someone else
Article

Your browser obeys someone else

Chrome disabling uBlock Origin was not a vendor choice to escape but a structure to see: software resolved by reference, executed without revalidating trust.

The .docx in your webmail preview pane
Article

The .docx in your webmail preview pane

Browser-side OOXML rendering converts trusted document parsers into renderer-context exploit primitives. The detection stack does not see the boundary cross.

Your SSD is leaking what you're doing
Article

Your SSD is leaking what you're doing

How websites can use SSD response timing as a covert channel to infer user activity, and what browsers and users can do about it.

Your VPN extension trusts every website you visit
Article

Your VPN extension trusts every website you visit

A hardcoded trigger word in a million-install Chrome VPN extension let any website disable the tunnel, change exit nodes, and read open tabs.

The boundary no longer holds
Article

The boundary no longer holds

A board-level brief on CVE-2026-40369, the twelve-byte browser sandbox escape, and the control assumptions senior leadership must now revisit.

Chrome's fourth 2026 zero-day ships mid-cycle
Article

Chrome's fourth 2026 zero-day ships mid-cycle

Google's fourth exploited Chrome zero-day of 2026 patches a V8 type confusion bug. The real risk is the patch-to-deployment window.

Article

Chrome's fourth zero-day of 2026 ships mid-cycle

Fourth Chrome zero-day of 2026 is a V8 type confusion. Inside the exploit chain, sandbox escape, and the patch gap attackers are weaponising right now.

CVE-2025-1234: Type Confusion in V8 JavaScript Engine Exploited in the Wild
Article

CVE-2025-1234: Type Confusion in V8 JavaScript Engine Exploited in the Wild

CVE-2025-1234: Type confusion in V8 exploited in the wild, enabling arbitrary code execution via JIT deoptimization. MITRE T1059.004, EDR blind spots, and post-patch exposure.