Browser Security
The latest Browser Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Palo Alto's Prisma SASE 4.0 Targets AI-Driven Browser Attacks and Rogue SaaS Agents
Palo Alto Networks has drawn a clear line in the SASE arms race. On September 4, 2025, the company launched Prisma SASE 4.0, a major platform refresh that frames the next phase of enterprise security...
Firefox 115 ESR Gets Another Lifeline: Security Updates for Windows 7 Through March 2026
Mozilla has once again extended the support window for Firefox 115 ESR, giving users on Windows 7, Windows 8/8.1, and macOS 10.12-10.14 a reprieve until at least March 2026. The move, confirmed in...
Chrome’s AI Security Line: Hallucinations Are Feedback, Prompt Injection Is a Breach
Google quietly revised Chrome’s public security FAQ last week, inserting a new “AI Features” section that finally tells bug hunters and enterprises exactly how the browser team will triage...
Chrome 139 Seals High-Severity V8 Out-of-Bounds Write CVE-2025-9132, Enterprises Scramble to Patch Edge
Google on August 19 shipped Chrome 139.0.7258.138 to patch a high-severity out-of-bounds write in its V8 JavaScript engine, tracked as CVE-2025-9132, that could let attackers execute arbitrary code...
Edge Canary Flags Reveal Microsoft's Plan to Sync Passkeys Across Devices via Microsoft Account
Microsoft has begun testing a significant upgrade to Edge that would allow the browser to sync passkeys across devices, signaling a major step toward a passwordless future. The latest Canary builds...
Google Chrome 139.0.7258.127 Plugs Aura Use-After-Free (CVE-2025-8882) and Other High-Severity Bugs
Google has deployed a critical stable-channel update for Chrome, version 139.0.7258.127, closing a use-after-free vulnerability in the Aura UI component tracked as CVE-2025-8882. The patch also...
Urgent Chrome 139.0.7258.127 Update Closes V8 Race Condition (CVE-2025-8880) — Patch Now for Windows, Edge, and Chromium Browsers
On August 12, 2025, Google rushed out Chrome 139.0.7258.127 with an urgent fix for CVE-2025-8880 — a high-severity race condition in the V8 JavaScript engine that could hand remote attackers the...
Chrome's File Picker Cross-Origin Leak Prompts Emergency Patch for Windows Browsers
A critical logic flaw in Chromium's File Picker—one of the browser's most sensitive UI components—can be weaponized to leak data across origins, forcing Google and Microsoft to ship urgent...
Microsoft Flags UI Spoofing Vulnerability CVE-2025-49755 in Edge for Android
Microsoft’s Security Response Center has disclosed CVE-2025-49755, a user-interface spoofing flaw in Microsoft Edge (Chromium-based) for Android that could let attackers trick users into handing...
Google Blocks Fingerprinting Scripts in Chrome Incognito With a Masked Domain List
Google has begun testing a new Incognito-mode protection that blocks third-party scripts from using browser fingerprinting techniques to re-identify users across sites. The feature, called Script...
Microsoft's Edge Lifeline for Windows 10 Until 2028 Buys Time, Not Security
Microsoft has drawn a bright line between its browser and its operating system. In a quiet update to its lifecycle policy, the company confirmed that Microsoft Edge and the WebView2 runtime will...
Microsoft Confirms Free Edge and WebView2 Updates for Windows 10 Through 2028, No ESU Required
Microsoft has officially decoupled the servicing lifecycle of its Edge browser and WebView2 runtime from the Windows 10 operating system, confirming that both will receive free updates—including...