Blink is a technology platform tracked across 12 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity July 1, 2026.
Blink is the open-source web rendering engine used by Chromium-based browsers and applications, handling layout, rendering, and JavaScript execution. As a core web platform component, security flaws in Blink/Chromium can enable remote code execution, crashes, or sandbox escapes affecting large user bases. The recent coverage centers on Chromium/CEF vulnerabilities and patching efforts, underscoring Blink’s critical role in web security.
CVE-2026-2441 is a zero-day CSS vulnerability affecting all Chromium-based browsers, allowing attackers to exploit a use-after-free condition in the Blink rendering engine. This vulnerability enables the theft of…
On June 25, 2026, three critical vulnerabilities were published affecting Chromium version 149.0.7827.200, specifically CVE-2026-13281 (Integer overflow in Mojo), CVE-2026-13282 (Use after free in Payments), and…
The TierOne dark web forum has initiated an article contest offering a total prize pool of $10,000 for submissions focused on vulnerability exploitation. The contest runs from April 13, 2026, to May 14, 2026, with…
Fedora has released updates for Chromium, addressing several vulnerabilities including CVE-2026-0899, which involves out-of-bounds memory access in V8. Other issues include inappropriate implementations and insufficient…
A critical race condition vulnerability, identified as CVE-2026-1220, has been discovered in Chromium, impacting users of Fedora 43. The vulnerability affects the V8 engine of the browser, prompting an urgent update to…
Two high-severity vulnerabilities, CVE-2025-14765 and CVE-2025-14766, have been identified in Chromium, impacting Fedora users. CVE-2025-14765 involves a use-after-free issue in WebGPU, while CVE-2025-14766 relates to…
Several high-risk vulnerabilities have been identified in Chromium and its embeddable version, CEF, affecting various implementations. Key issues include type confusion and inappropriate implementations in the V8…
A series of high severity vulnerabilities have been reported in Chromium and its embeddable version, CEF. Key issues include inappropriate implementations and out-of-bounds writes affecting various components, with CVEs…
A newly discovered exploit named Brash can crash Chromium-based browsers, including Google Chrome and Microsoft Edge, by overloading the tab title API. Disclosed by security researcher Jose Pino, this vulnerability…
Security researchers have identified a vulnerability in Cursor, an AI-powered code editor, that allows rogue Model Context Protocol (MCP) servers to inject malicious code into its internal browser. This exploit can…