View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Chrome DevTools use-after-free enables sandbox escape

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • AWS publishes incident response guide for CloudTrail investigations โ€“ Part 1
    AWS has published a guide walking through how to investigate security incidents using AWS CloudTrail logs.

    • Applies to AWS customers and security teams investigating suspicious activity in their AWS environments
    • The guide explains which CloudTrail log fields matter and how to interpret them when investigating incidents
    • Part 1 walks through real-world scenarios showing how to analyze CloudTrail events to uncover the full scope of an incident
      ๐Ÿ“Ž Coverage: aws.amazon.com ยท ๐Ÿ‘ via AWS Security Blog
  • Coder's registry infrastructure compromised to push malicious modules โ€” BleepingComputer

  • Large Enterprises Targeted in Fake Merger & Acquisition Scams โ€” Dark Reading

  • What We Missed: Did ShinyHunters 'Breach' ReliaQuest? โ€” Dark Reading

  • ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories โ€” The Hacker News

  • The G7 tells industry to hurry up and prep for post-quantum encryption โ€” CyberScoop

  • The story behind the intelligence โ€” Cisco Talos

  • Divide-by-zero in Xpdf 4.06 due to zero-height Type 3 glyphDivide-by-zero in ... โ€” CVE ThreatInt

  • MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap ... โ€” CVE ThreatInt

  • stream-json: pick/ignore/filter/replace filters are O(depth2) on nested input... โ€” CVE ThreatInt

  • Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the av... โ€” CVE ThreatInt

  • Use of released resource in Mobile in Google Chrome on on Android prior to 15... โ€” CVE ThreatInt

  • Improper input validation in Transactions Platform in Google Chrome on on iOS... โ€” CVE ThreatInt

  • Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed... โ€” CVE ThreatInt

  • Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.79... โ€” CVE ThreatInt

  • Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.79... โ€” CVE ThreatInt

  • Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote... โ€” CVE ThreatInt

  • Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed... โ€” CVE ThreatInt

  • Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote... โ€” CVE ThreatInt

  • R2R 3.6.6 SQL Injection via Retrieval Search Filter KeyR2R through 3.6.6 cont... โ€” CVE ThreatInt

  • itsourcecode Online Medicine Delivery System index.php cross site scriptingA ... โ€” CVE ThreatInt

  • Medplum - Exposure of OAuth client secret via dynamic registration endpoint i... โ€” CVE ThreatInt

  • Incident response guide for AWS CloudTrail investigations โ€“ Part 2 โ€” AWS Security Blog

  • Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models โ€” Cloudflare Blog

  • @ jpsays Any insights on same subnet RDP inbound 3389 to a desktop listening for TermServ would not respond to SYN, and... โ€” @SwiftOnSecurity@infosec.exchange

  • python-jose HS256 Token Forgery (CVE-2026-85394) โ€” thehackerwire.com (discovered)

  • GeoNetwork Critical RCE via XSLT Processor Misconfiguration (CVE-2026-58400) โ€” thehackerwire.com (discovered)

  • Bankrupting the Adversary: Why Cybersecurity is an Economic War โ€” securityboulevard.com (discovered)

  • Millions of US/Canadian drivers license being sold - Who do we think got breached? Id.me? Verify.me? โ€” r/cybersecurity

  • Breaking Down Appsec Part 1: Application Context โ€” r/cybersecurity

  • newbie question here about cyber security and the future โ€” r/cybersecurity

  • Network pentesters with 2โ€“3 years of experience: What does your day-to-day work actually look like? โ€” r/cybersecurity

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Chrome DevTools use-after-free (CVE-2026-85042) allows sandbox-escape code execution, fixed in 152.0.7977.82 โ€” chromereleases.googleblog.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check