Chrome – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 30 Aug 2025 12:41:20 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Chrome – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Google’s new Passwords app means I can finally ditch Chrome https://earlybirdsinvest.com/googles-new-passwords-app-means-i-can-finally-ditch-chrome/ https://earlybirdsinvest.com/googles-new-passwords-app-means-i-can-finally-ditch-chrome/#respond Sat, 30 Aug 2025 12:41:20 +0000 https://earlybirdsinvest.com/googles-new-passwords-app-means-i-can-finally-ditch-chrome/
google password manager app shortcut on a smartphone home screen

Megan Ellis / Android Authority

I’ve been on a mission to de-Google my life as much as possible in an attempt to control how much information a single company has about me. While there are some essential Google services I will never part with, switching my browser from Chrome has been a priority.

Which password manager do you use to save your Android passwords?

25 votes

I prefer Brave, but I was tethered to Chrome

an ai summary in brave on a smartphone screen

Megan Ellis / Android Authority

I have never regretted the switch to Brave. However, Chrome remained in my app rotation for one simple reason: I have hundreds of passwords saved in the Password Manager. While it’s possible to export passwords to another browser, Password Manager is also built into Android. This integration allows you to save passwords, generate secure password suggestions, and access login details across devices.

I’m glad I switched to Brave, but password management on Android kept me tethered to Chrome.

This also means that Password Manager has been essential for my Android phones. When an OEM doesn’t have its own version of a credential manager, Google’s Password Manager remains the default way to save and access app passwords. Even when an alternative manager was available, I used Google’s solution wherever possible to make my details easily accessible across phones from different manufacturers.

I could technically access the passwords by searching through my phone’s settings and finding my Google account preferences, but the process was different for each device and resulted in me visiting a variety of different menus before finding the right one. This is why I kept Chrome around. If I wanted to access my app passwords easily, I needed to open Chrome and access them there. But the standalone Password Manager app has changed that.

Google Password Manager app makes accessing Android passwords easier

google password manager play store listing

Megan Ellis / Android Authority

Google Password Manager now exists as a standalone app that you can download from the Google Play Store. Not only does this make it easier to access the service on your home screen and through your app drawer, but it also makes accessing the service easier overall.

I was initially concerned that the app only functioned as a shortcut to the password manager within Chrome. I’ve since disabled Chrome on my smartphone to see whether this was the case. I was happy to discover that I can still access the password manager without needing Chrome. I was also able to sign up for a new app, generate a password through the Password Manager pop-up, and save the password to the service.

Google’s Password Manager app works even if you have Chrome disabled on your smartphone.

Likewise, I can still access the most important features of the service, including account credentials, the checkup tool, and autofill settings.

The only other reason I kept Chrome around was to easily access Google Search when I needed shopping links or better local results. I love Brave Search, but it doesn’t provide as many local results and local shop listings as I would like. However, I don’t need Chrome to access Google — I can just add a shortcut to the search engine in Brave.

With the introduction of the standalone Password Manager app, my last reason to keep Chrome around no longer applies. The anxiety I felt when considering completely leaving Chrome behind is gone.

However, there are drawbacks. Even though Google Password Manager is now a standalone app, this doesn’t mean it acts like other credential management apps. When I use Brave, the passwords I enter save to Brave’s built-in password manager, even when I’m using my phone. Google’s autofill feature also only works when I’m using an Android app that requires a login, or when I’m using Chrome.

So, when I want to log in to a site using Brave, I need to open Google’s app to copy over the credentials and paste them separately to the browser. Overall, though, I’m glad I no longer need to keep Chrome installed to do this.

I may eventually move to a different password manager

create passkey prompt ios bitwarden 2

Calvin Wankhede / Android Authority

While Google Password Manager is the most convenient password manager to use across devices, it isn’t necessarily the most secure. There are plenty of great password managers to choose from, many of which offer free plans. Since I’ve also switched from Chrome as my default browser on my computer, I need a manager I can use across devices and browsers. A dedicated password manager app will also allow me to use the autofill feature regardless of which browser I’m using.

But to be honest, I find comfort in familiarity, so it will take time for me to truly make the jump. I’m eager to try out Proton Pass due to the company’s focus on privacy. The password manager also offers benefits like email aliases and an integrated two-factor authentication (2FA) feature. It will also let me import my passwords from multiple browsers and generate strong passwords for accounts.

However, before I make the switch to an alternative, I will need time to test it and see that it suits my needs. At the same time, I’m glad that Google’s new standalone app makes it possible for me to easily store Android credentials without needing to use Chrome to access them anymore.

I no longer feel stuck and bound to Chrome, which in turn has made it easier to envision more ways I can reduce my reliance on Google. I want to use a service because it offers the best features, not because I’m simply locked into the ecosystem.

Thank you for being part of our community. Read our Comment Policy before posting.

]]>
https://earlybirdsinvest.com/googles-new-passwords-app-means-i-can-finally-ditch-chrome/feed/ 0 55890
Google patches new Chrome zero-day bug exploited in attacks https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/ https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/#respond Tue, 03 Jun 2025 11:09:32 +0000 https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/

Google Chrome

Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year.

“Google is aware that an exploit for CVE-2025-5419 exists in the wild,” the company warned in a security advisory published on Monday.

This high-severity vulnerability is caused by an out-of-bounds read and write weakness in Chrome’s V8 JavaScript engine, reported one week ago by Clement Lecigne and Benoît Sevens of Google’s Threat Analysis Group.

Google says the issue was mitigated one day later by a configuration change the company pushed to the Stable channel across all Chrome platforms.

On Monday, it also fixed the zero-day with the release of 137.0.7151.68/.69 for Windows/Mac and 137.0.7151.68 for Linux, versions that are rolling out to users in the Stable Desktop channel over the coming weeks.

While Chrome will automatically update when new security patches are available, users can speed up the process by going to the Chrome menu > Help > About Google Chrome, letting the update finish, and clicking the ‘Relaunch’ button to install it immediately.

Chrome 137.0.7151.69

​While Google has already confirmed that CVE-2025-5419 is being exploited in the wild, the company will not share additional information regarding these attacks until more users have patched their browsers.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

This is Google’s third Chrome zero-day vulnerability since the start of the year, with two more patched in March and May.

The first, a high-severity sandbox escape flaw (CVE-2025-2783) discovered by Kaspersky’s Boris Larin and Igor Kuznetsov, was used to deploy malware in espionage attacks targeting Russian government organizations and media outlets.

The company released another set of emergency security updates in May to patch a Chrome zero-day that could let attackers take over accounts following successful exploitation.

Last year, Google patched 10 zero-days that were either demoed during the Pwn2Own hacking competition or exploited in attacks.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/feed/ 0 39879
Google fixes high severity Chrome flaw with public exploit https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/ https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/#respond Thu, 15 May 2025 12:53:17 +0000 https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/

Google Chrome

Google has released emergency security updates to patch a high-severity vulnerability in the Chrome web browser that could lead to full account takeover following successful exploitation.

While it’s unclear if this security flaw has been used in attacks, the company warned that it has a public exploit, which is how it usually hints at active exploitation.

“Google is aware of reports that an exploit for CVE-2025-4664 exists in the wild,” Google said in a Wednesday security advisory.

The vulnerability was discovered by Solidlab security researcher Vsevolod Kokorin and is described as an insufficient policy enforcement in Google Chrome’s Loader component that lets remote attackers leak cross-origin data via maliciously crafted HTML pages.

“You probably know that unlike other browsers, Chrome resolves the Link header on subresource requests. But what’s the problem? The issue is that the Link header can set a referrer-policy. We can specify unsafe-url and capture the full query parameters,” Kokorin explained.

“Query parameters can contain sensitive data – for example, in OAuth flows, this might lead to an Account Takeover. Developers rarely consider the possibility of stealing query parameters via an image from a 3rd-party resource.”

Leaked OAuth access token
Leaked OAuth access token (Vsevolod Kokorin)

​Google fixed the flaw for users in the Stable Desktop channel, with patched versions (136.0.7103.113 for Windows/Linux and 136.0.7103.114 for macOS) rolling out to users worldwide.

Although the company says the security updates will roll out over the coming days and weeks, they were immediately available when BleepingComputer checked for updates.

Users who don’t want to update Chrome manually can also let the browser automatically check for new updates and install them after the next launch.

In March, ​Google also fixed a high-severity Chrome zero-day bug (CVE-2025-2783) that was abused to deploy malware in espionage attacks targeting Russian government organizations, media outlets, and educational institutions.

Kaspersky researchers who discovered the actively exploited zero-day said that the attackers use CVE-2025-2783 exploits to bypass Chrome sandbox protections and infect targets with malware.

Last year, Google patched 10 zero-days disclosed during the Pwn2Own hacking competition or exploited in attacks.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/feed/ 0 36364
Chrome for Android is getting extensions, but not like you’d expect https://earlybirdsinvest.com/chrome-for-android-is-getting-extensions-but-not-like-youd-expect/ https://earlybirdsinvest.com/chrome-for-android-is-getting-extensions-but-not-like-youd-expect/#respond Thu, 03 Apr 2025 13:04:22 +0000 https://earlybirdsinvest.com/chrome-for-android-is-getting-extensions-but-not-like-youd-expect/

What you need to know

  • Google is working on a desktop-style Chrome for Android with extension support, something mobile Chrome has been missing.
  • This new version is designed for larger Android devices like Chromebooks, and it’s a big step toward closing the gap between mobile and desktop browsing.
  • It’s still a bit rough—no easy way to manage extensions, no toolbar button, and installing them isn’t as smooth as on desktop.

Google is apparently working on a unique version of Chrome for Android with a full-fledged desktop-style interface. This version stands out by finally bringing browser extension support, something the current mobile Chrome completely lacks.

Google Chrome might be huge on Android, but it has always lagged behind its desktop version, especially when it comes to extensions. Now, Google is working on changing that with a desktop-class Chrome for Android, finally bringing extension support into the mix, as per Mishaal Rahman over at Android Authority.

Thanks to a recent code tweak, users can now manually install extensions by simply dragging and dropping .crx files into the chrome://extensions page.

Built for big screens

browser extension support for Chrome on Android

(Image credit: Android Authority)

True to its name and the reports from late 2024, the Desktop Android version of Chrome is built to bring the browser’s core features to large-screen Android devices, including Chromebooks and other computers. With Chrome OS on its way out, a solid replacement is more important than ever.

Rahman has been putting these test Chrome builds through their paces, and the results speak for themselves. He’s already got extensions like Dark Reader, Keepa, and uBlock Origin up and running, proving that an Android-based Chrome can fully support extensions.

Despite the progress, there are still a few hiccups. For one, users can’t access extension settings yet, and there’s no toolbar button to easily toggle extensions. Additionally, without a Chrome Web Store equivalent for Android, installing extensions still feels a bit basic. It works, but it’s definitely not polished.

It appears that Google is currently putting all its energy into just making extensions work at all. So, to check on or manage your extensions, you’ll need to head straight to the chrome://extensions page.

Regular phones? Don’t hold your breath

Adding extension support to Chrome for Android is a big step toward matching the desktop browsing experience. Sure, it’s still a bit rough around the edges, but make no mistake: this is the foundation for something huge.

That said, these changes probably won’t lead to extensions being available on Chrome for regular Android phones. Google has purposely stayed away from adding extension support on Android, unlike Firefox and Microsoft Edge, signaling a clear strategy behind the decision.

]]>
https://earlybirdsinvest.com/chrome-for-android-is-getting-extensions-but-not-like-youd-expect/feed/ 0 28779
StilachiRAT Malware Targets Crypto Wallet Extensions on Chrome https://earlybirdsinvest.com/stilachirat-malware-targets-crypto-wallet-extensions-on-chrome/ https://earlybirdsinvest.com/stilachirat-malware-targets-crypto-wallet-extensions-on-chrome/#respond Wed, 19 Mar 2025 07:08:25 +0000 https://earlybirdsinvest.com/stilachirat-malware-targets-crypto-wallet-extensions-on-chrome/

A newly identified remote access Trojan (RAT) is being used to steal information from cryptocurrency wallets stored in Google Chrome extensions, according to Microsoft.

The malware, called StilachiRAT, has been found in at least 20 different wallet extensions, including popular ones like Coinbase



$1.78B

Wallet, OKX



$2.39B

Wallet, MetaMask, and Trust Wallet.

Microsoft’s security team first identified the threat in November 2024 and found that it is capable of extracting sensitive information from infected devices. Once active, it scans a system for crypto wallet extensions and gathers sensitive information, such as login credentials, wallet data, and clipboard content. By monitoring copied text, it can capture passwords and private keys.

What is Shiba Inu Coin? (Explained with Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The malware also includes stealth features to make detection difficult. It can erase system logs and identify whether it is running in a virtual environment, which prevents cybersecurity analysts from studying it easily.

Microsoft examined its WWStartupCtrl64.dll module and confirmed that StilachiRAT uses multiple techniques to access stored data and operate undetected.

Microsoft has not determined who is behind the malware. However, the company warns that while it is not yet widely spread, its ability to operate quietly makes it a concern. To reduce the risk of infection, Microsoft recommends using antivirus software, enabling cloud-based security protections, and keeping anti-malware tools active.

Kaspersky, a cybersecurity firm, recently reported that hackers used SilentCryptoMiner, a crypto-mining malware, to steal crypto from YouTube creators. How did they use the malware? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/stilachirat-malware-targets-crypto-wallet-extensions-on-chrome/feed/ 0 25980
Microsoft uncovers new trojan targeting crypto wallet extensions on chrome https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/ https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/#respond Wed, 19 Mar 2025 02:39:43 +0000 https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/

Microsoft researchers have identified a new remote access trojan (RAT) named StilachiRAT, designed to steal cryptocurrency wallet data, credentials, and system information while maintaining persistent access to compromised devices, the company disclosed on March 17.

The malware, first detected in November 2024, employs stealth techniques and anti-forensic measures to evade detection.

While Microsoft has not yet attributed StilachiRAT to a known threat actor, security experts warn that its capabilities could pose a significant cybersecurity risk, particularly to users handling crypto.

Sophisticated threat

StilachiRAT is capable of scanning for and extracting data from 20 different cryptocurrency wallet extensions in Google Chrome, including MetaMask, Trust Wallet, and Coinbase Wallet, allowing attackers to access stored funds.

Additionally, the malware decrypts saved Chrome passwords, monitors clipboard activity for sensitive financial data, and establishes remote command-and-control (C2) connections via TCP ports 53, 443, and 16000 to execute commands on infected machines.

The RAT also monitors active Remote Desktop Protocol (RDP) sessions, impersonates users by duplicating security tokens, and enables lateral movement across networks — an especially dangerous feature for enterprise environments.

Persistence mechanisms include modifying Windows service settings and launching watchdog threads to reinstate itself if removed.

To further evade detection, StilachiRAT clears system event logs, disguises API calls, and delays its initial connection to C2 servers by two hours. It also searches for analysis tools such as tcpview.exe and halts execution if they are present, making forensic analysis more difficult.

Mitigation strategies and response

Microsoft advised users to download software only from official sources, as malware like StilachiRAT can masquerade as legitimate applications.

The company also recommended enabling network protection in Microsoft Defender for Endpoint and activating Safe Links and Safe Attachments in Microsoft 365 to guard against phishing-based malware distribution.

Microsoft Defender XDR has been updated to detect StilachiRAT activity. Security professionals are urged to monitor network traffic for unusual connections, inspect system modifications, and track unauthorized service installations that could indicate an infection.

While Microsoft has not observed widespread distribution of StilachiRAT, the company warned that threat actors frequently evolve their malware to bypass security measures. Microsoft said it is continuing to monitor the threat and will provide further updates through its Threat Intelligence Blog.

Mentioned in this article
XRP Turbo
]]>
https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/feed/ 0 25941
Google Chrome disables uBlock Origin for some in Manifest v3 rollout https://earlybirdsinvest.com/google-chrome-disables-ublock-origin-for-some-in-manifest-v3-rollout/ https://earlybirdsinvest.com/google-chrome-disables-ublock-origin-for-some-in-manifest-v3-rollout/#respond Sat, 22 Feb 2025 14:19:51 +0000 https://earlybirdsinvest.com/google-chrome-disables-ublock-origin-for-some-in-manifest-v3-rollout/

Google Chrome

Google continues its rollout of gradually disabling uBlock Origin and other Manifest V2-based extensions in the Chrome web browser as part of its efforts to push users to Manifest V3-based extensions.

For those unaware, Manifest V3 is Chrome’s latest extension specification and is designed to limit extension access to user network requests, block developers from utilizing remote content, and improve overall performance.

While Manifest V3 is supposed to benefit end users, it comes at the cost of functionality, as it imposes stricter limitations on browser extensions, particularly ad blockers and privacy-focused tools.

Due to this, some immensely popular Google Chrome extensions, like uBlock Origin, are now gradually being automatically turned off in users’ browsers worldwide.

Just today, some of BleepingComputer’s devices found that uBlock Origin was automatically disabled, stating it was no longer supported. Our only options were to remove the extension or manage it. 

While the first option removes the extension from Chrome, the second simply redirects you to the extensions page.

Google turns off uBlock Origin extension due to Manifest V3 rollout
Google turns off uBlock Origin extension due to Manifest V3 rollout
Source: BleepingComputer

In a Reddit thread from yesterday, other Google Chrome users also pointed out that uBlock Origin and other unsupported extensions are now automatically being turned off.

However, this does not appear to be the case for everyone, as some devices used by BleepingComputer continue to use uBlock without any issues.

Google is gradually killing off Manifest V2 extensions

Google has previously told BleepingComputer that the disabling of Manifest V2 extensions is a gradual rollout process, which is why the extensions may still work for some users. 

For those who need more time, Google will let the enterprise and certain users continue using Manifest V2 extensions until June 2025 through a special group policy. For everyone else, the rollout of Manifest V3 is already in progress, and Chrome will keep encouraging users to move away from older extensions.

If you’re affected by Google’s Manifest V2 deprecation, you can switch to Manifest V3-supported extensions, such as the uBlock Origin Lite (uBOL), which the uBlock Origin developer has created.

However, if you prefer uBlock Origin’s advanced filtering, you may find the Lite version too limited.

BleepingComputer emailed Google with questions about this gradual rollout, why it was done this way, and when the rollout will be completed. We will update the story if we receive a response.

]]>
https://earlybirdsinvest.com/google-chrome-disables-ublock-origin-for-some-in-manifest-v3-rollout/feed/ 0 21154