Tech News
← Home  ·  All topics

Chrome

46 GoKawiil briefs on this topic

UK CMA proposes yearly search-choice prompts for Android and Chrome

The UK Competition and Markets Authority has proposed requiring Google and Android device makers to present search-engine choice screens when phones or Chrome are first set up, followed by annual prompts. The plan also calls for offering users a choice of AI assistants that meet certain security standards, and for requiring search providers to clearly attribute publisher content shown in results. The proposals build on measures introduced earlier in 2026, including a June 3rd rule letting publishers opt out of AI results.

GoKawiil Original How to Vet a Browser Extension Before You Install It

An extension can read and change everything you do in the browser, including pages you are signed into. That is worth about ninety seconds of checking first.

Google launches Googlebook OS laptops with Acer, Asus, Dell, HP and Lenovo

Google has officially unveiled Googlebook, a new laptop platform built on Android and Chrome OS foundations, previously known internally as Aluminium OS. Acer, Asus, Dell, HP and Lenovo have all announced flagship Googlebook laptops starting at $899, with US sales beginning October 4 and pre-orders already open at the Google Store, Best Buy, and select retailers.

Third-party tool turns Chrome's new tab into a customizable bookmark hub

A software utility lets users replace their browser's default new tab page with a personalized dashboard for organizing bookmarks and frequently visited sites. The tool works across most major browsers, not just Chrome, giving users a consistent launchpad experience regardless of which browser they use.

AI-Assisted Bug Hunting Triggers Record Surge in Software Vulnerability Disclosures

Major tech firms including Microsoft, Oracle and Google reported unprecedented numbers of security patches this year, with Microsoft issuing 974 CVE fixes this month alone and Oracle shipping 1,448 patches in July compared to 309 a year earlier. Analysts tracking cve.icu counted 66,401 confirmed vulnerabilities as of this week, nearly double last September's tally, a jump attributed largely to AI tools now used for automated bug discovery.

BragJack flaw let malicious extensions hijack AI browser agents in five browsers

Security researcher Gal Weizman of Forever Security found that a single malicious browser extension could take over AI assistants embedded in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome, using Chromium's declarativeNetRequest feature to manipulate trusted network traffic without any user interaction. The technique, called BragJack, earned Weizman over $20,000 in bug bounties across the five vendors and generated two CVEs, with Google and Microsoft having already patched the issues.

Snapdrop lets users transfer files between devices without accounts or apps

Snapdrop is a browser-based tool that lets people send files directly between nearby devices without creating an account or installing software. The service works via local network connections, and on Chrome it may briefly request microphone access to help detect nearby devices, though no audio is recorded or transmitted.

GitHub Users Report UI Bugs in PR Counts and Org Membership Pagination

A developer flagged two recurring GitHub interface bugs: one that overcounts pull requests in the repository tab, especially after merges, even though the correct count appears elsewhere on the same page, and another affecting a pop-up window for org membership selection that fails to properly paginate, blocking access to org pages beyond the first. The user worked around the pagination issue by using JavaScript to force navigation within the pop-up, since Chrome wouldn't allow manual editing of its address bar.

KREMLIN toolkit forces fake Chrome and Edge extensions onto Brazilian banking targets

Elastic Security Labs uncovered a malware toolkit called KREMLIN, active since mid-2025, that tricks victims into opening fake invoice or receipt files to install malicious Chrome and Edge extensions without any user approval. The toolkit recreates Chromium's cryptographic integrity checks so the browser treats the rogue extension as legitimate, then harvests login credentials, session tokens and other sensitive data. Elastic ties the operation to a Brazilian group that has run at least seven campaigns impersonating 12 banks since May.

Developer questions JPEG XL's future as a mainstream Web image format

A compression engineer revisits JPEG XL's standing on the Web, noting that despite its technical strengths over JPEG and WebP, Chrome dropped support in 2023. He points out that a new Rust-based JPEG XL decoder has since appeared in Firefox and parts of Chrome, partly to avoid repeating a security flaw once found in WebP, but argues this alone doesn't settle whether JPEG XL deserves broad Web adoption.

Roblox to launch browser play by 2026, offline mode by 2027

At its annual Developers Conference, Roblox announced plans to let players jump into games directly from a browser without downloading anything, starting with Chrome by the end of 2026. In mid-2027, the platform will also add offline solo play for spotty-connection areas, with early access arriving sooner, alongside a push to let creators publish standalone apps across mobile, PC and consoles under a 'Play Roblox Everywhere' initiative.

LinkedIn defeats browser-extension scanning lawsuits over lack of standing

A federal judge in California dismissed two proposed class actions accusing LinkedIn of illegally scanning users' browser extensions, ruling that the plaintiffs failed to show they actually had extensions installed that leaked private data to the company. Judge Vince Chhabria allowed the plaintiffs to amend their complaints but expressed skepticism they could ever establish a valid privacy claim, given that browser extensions are voluntarily installed and inherently share data with websites. One plaintiff's attorney says he may refile in state court or appeal to the Ninth Circuit.