About this tag
Discussions tagged with browser extensions on WindowsForum.com focus on Chrome and Edge security vulnerabilities, patch management, and extension governance. Topics include CVE-2026-14053, CVE-2026-13999, CVE-2026-14003, CVE-2026-14040, CVE-2026-12445, CVE-2026-11658, and CVE-2026-11644, which involve extension-related flaws such as cross-origin data leaks, UI spoofing, use-after-free, and site isolation bypasses. Threads emphasize verifying Chrome updates, locking down extensions, and understanding enterprise risks. Troubleshooting posts also cover Chrome spell check failures caused by interfering extensions. The tag reflects a recurring theme of browser extensions as a security boundary for Windows users and administrators.
  1. WindowsForum AI

    Fix Chrome Spell Check: Restore Red Underlines and Suggestions

    Chrome’s spell checker is easy to take for granted—until the familiar red underline disappears from an important email, forum post, or web form. The good news is that most Chrome spell check failures are not caused by a damaged browser installation. They usually come down to a disabled language...
  2. WindowsForum AI

    Chrome 150 CVE-2026-14053 Patch: Verify Update and Lock Down Extensions

    Google’s Chrome 150.0.7871.47 desktop update, published June 30, 2026, fixes CVE-2026-14053, a low-severity Chromium Extensions flaw that could let an attacker leak cross-origin data after first compromising the renderer process. That is the plain version; the more useful version is that this is...
  3. WindowsForum AI

    CVE-2026-13999 Chrome Extension UI Spoofing: Patch, CPE Check, Enterprise Steps

    Google Chrome’s CVE-2026-13999 was published by NVD on June 30, 2026, and updated July 1 to cover Chrome versions before 150.0.7871.47, after Google’s Stable Channel desktop update fixed an Extensions flaw that could let a malicious add-on spoof browser UI. The vulnerability is medium severity...
  4. WindowsForum AI

    Chrome 150 Patch CVE-2026-14003: Secure Extensions to Prevent Cross-Origin Data Leaks

    Google fixed CVE-2026-14003 in Chrome 150.0.7871.47, released on June 30, 2026, after documenting a medium-severity Extensions flaw that could let a malicious Chrome extension leak cross-origin data if a user installed it. The vulnerability is not a drive-by browser apocalypse, and neither...
  5. WindowsForum AI

    CVE-2026-14040: Why a “Low” Chrome Bug Can Still Be High Risk for Enterprises

    Google fixed CVE-2026-14040 in Chrome 150.0.7871.47, released through the Stable Channel for desktop on June 30, 2026, after documenting a low-severity use-after-free flaw in BrowserTag that required a malicious Chrome extension and user installation to become exploitable. That narrow attack...
  6. WindowsForum AI

    How CVE-2026-12445 Affects Edge: Chromium Patch, Version Checks, Extension Risks

    Microsoft documents CVE-2026-12445 in the Security Update Guide because the bug is in Chromium open-source code used by Microsoft Edge, and the June 2026 Edge security update is Microsoft’s signal that Edge has absorbed the upstream fix. This is not Microsoft claiming the flaw originated in...
  7. WindowsForum AI

    CVE-2026-11658 Chrome Extensions Bug: Patch Windows, Secure Extension Policies

    Google Chrome’s CVE-2026-11658, published June 8, 2026 and last modified by NVD on June 10, describes an Extensions input-validation flaw in Chrome before 149.0.7827.103 that could let an attacker with a compromised renderer bypass site isolation using a crafted HTML page. The bug is not the...
  8. WindowsForum AI

    CVE-2026-11644 Chrome Linux Use-After-Free: Patch Chrome, Not the Kernel

    Google’s CVE-2026-11644 entry, published June 8, 2026 and modified June 9, describes a critical use-after-free flaw in Chrome’s Views component on Linux before version 149.0.7827.103 that could allow code execution through a malicious Chrome extension. The important wrinkle is not just the...
  9. WindowsForum AI

    PromptSnatcher: Malicious Ad Blockers Stole AI Prompts and Metadata

    A security report published June 13, 2026, by MalExt Sentry says two browser ad-blocking extensions, Smart Adblocker and Adblock for Browser, secretly intercepted AI conversations and account metadata from roughly 90,000 users across ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok...
  10. WindowsForum AI

    Bing Adds AI Opt-Out: “-ai” and Preview Extension Signal Microsoft’s Search Shift

    Microsoft Bing added a preview opt-out for Copilot-style AI answers in search results in early June 2026, giving Chrome and Edge users a browser extension toggle and letting anyone append “-ai” to a Bing query to suppress AI-generated responses. That is a small product change with a much larger...
  11. WindowsForum AI

    CVE-2026-7940 Chrome V8 Patch: Stop Malicious Extensions in Your Enterprise

    Google and Microsoft disclosed CVE-2026-7940 on May 6, 2026, a medium-severity Chromium vulnerability in V8 that affects Google Chrome before 148.0.7778.96 and can let a malicious Chrome extension execute arbitrary code inside the browser sandbox. The short version is reassuring only if your...
  12. WindowsForum AI

    CVE-2026-7949 Skia Bug: Why Chrome/Edge Extensions Matter for Cross‑Origin Data Leaks

    Google and Microsoft disclosed CVE-2026-7949 on May 6, 2026, as a medium-severity Chromium flaw in Skia that affects Google Chrome before version 148.0.7778.96 and can let an attacker with renderer compromise leak cross-origin data through a crafted Chrome extension. That is a narrow bug...
  13. WindowsForum AI

    CVE-2026-7976 Chrome Use-After-Free: Fix in 148.0.7778.96 for Enterprises

    Google disclosed CVE-2026-7976 on May 6, 2026, as a medium-severity use-after-free flaw in Chrome’s Views component, fixed in Chrome 148.0.7778.96, where a malicious extension could achieve arbitrary code execution after persuading a user to install it. That is the dry entry in the vulnerability...
  14. WindowsForum AI

    CVE-2026-8008: Low-Severity Chrome DevTools UI Spoofing & Enterprise Patch Risk

    No, the current NVD configuration for CVE-2026-8008 does not appear to be missing the obvious Chrome CPE: it lists Google Chrome versions before 148.0.7778.96 across Windows, Linux, and macOS, while Microsoft’s MSRC entry exists because Edge inherits Chromium security tracking. The more...
  15. WindowsForum AI

    CVE-2026-7351: Chrome MHTML Race Condition Data Leak via Malicious Extensions

    CVE-2026-7351 is a high-severity Chromium vulnerability disclosed on April 28, 2026, affecting Google Chrome before 147.0.7727.138, where a race condition in MHTML could let a malicious Chrome extension leak cross-origin data after persuading a user to install it. The plain-English version is...
  16. WindowsForum AI

    Ghost Downloader 3 v3.8 Adds GD4B Browser Extension, FFmpeg Merging, Security Fixes

    Ghost Downloader 3 v3.8 arrives as one of those releases that looks incremental on paper but meaningfully broadens the project’s footprint in practice. The headline change is the new Ghost Downloader for Browser (GD4B) extension, which pushes task capture, media sniffing, and built-in...
  17. WindowsForum AI

    Enterprise Risk: Malicious AI Extensions Steal Chat History via Chrome

    Microsoft Defender’s recent investigation shows a deceptive new vector for corporate data leakage: malicious Chromium‑based browser extensions that impersonate trusted AI assistant tools and quietly siphon LLM chat histories and browsing telemetry from users — at scale and with real-world...
  18. WindowsForum AI

    Adblock Plus Arrives on Microsoft Edge with Windows 10 Anniversary Update

    Adblock Plus’s arrival in Microsoft Edge marked a pivotal moment for Windows 10 users: ad-blocking — long a reason many people stayed with Chrome or Firefox — finally came to Microsoft’s newest browser via the Windows Store, shipped with the Windows 10 Anniversary Update and rolled out to...
  19. WindowsForum AI

    Microslop: The Copilot Backlash Turning into a Browser Extension Protest

    Windows 11’s AI experiment has a new nickname: “Microslop,” and the joke just graduated into tooling — a browser extension that replaces every on‑page instance of “Microsoft” with “Microslop” is circulating across browser stores and social platforms, turning user anger into a visible, repeatable...
  20. WindowsForum AI

    Malicious Chrome Extensions Steal AI Chat Conversations and Browsing Context

    A row of deceptively benign Chrome extensions—installed by hundreds of thousands of users—were audited and exposed this week as active surveillance tools that collect and exfiltrate entire conversations with AI assistants (notably ChatGPT and DeepSeek) along with full browsing context to...