Hacktron reports that GPT-5.6 Sol Ultra built a complete Chrome/V8 exploit chain in a controlled test for $1,596.89 of model compute. The benchmark handed the model the source tree and the public security-fix commits, so the figure covers only the compute for one lab task.
Publishers:hacktron.ai · runtimewire.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+45
- Incentives70
- Confidence55
LastPass added shadow AI discovery and sensitive-data warnings to Business Max, run from the browser extension its customers already use. Teams on that tier get a warning and an audit log for browser AI use, and the release describes hard blocks only for web categories.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives75
- Confidence45
CVE-2026-87491 gives a crafted web page code execution inside Chrome's sandbox. The fix only takes effect when the browser restarts, and long-running sessions carry that exposure until they do.
Perspective Coverage
5 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence70
Google shipped 108 security fixes to the Chrome stable channel on September 22, eleven of them rated Critical and seven of those in graphics components a crafted page can drive. None were reported as exploited.
Reality
- Evidence72
- Adoption55
- Hype gap+10
- Incentives42
- Confidence70
Proofpoint says a shared toolkit called BlueMoon chained two V8 flaws that Chromium had fixed in public but Chrome had not yet shipped, plus a Windows kernel bug that elevates only on older builds.
Reality
- Evidence62
- Adoption58
- Hype gap+18
- Incentives66
- Confidence58
V8 says 60% of the Chrome exploits caught in the wild between 2021 and 2023 started in its own code, and that the logic bugs behind them are out of reach of both Rust and memory tagging, so the work went into containment.
Publishers:v8.dev
Reality
- Evidence62
- Adoption35
- Hype gap−10
- Incentives70
- Confidence58
Anthropic's red team says the scarce reverse-engineering skill that used to give defenders weeks is no longer the bottleneck. It measured that on Firefox and Windows kernel fixes, where a 19-day median gap counts as fast.
Reality
- Evidence55
- Adoption20
- Hype gap+22
- Incentives72
- Confidence48
Google says an exploit exists in the wild for CVE-2026-85046, a type confusion in Chrome's V8 engine, and it is the sixth Chrome zero-day the company has patched under active attack since January.
Perspective Coverage
9 publishers
- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence78
- Adoption52
- Hype gap+8
- Incentives58
- Confidence74
Two of the patched bugs need nothing more than a page load, according to Malwarebytes. Chrome applies fixes on restart, so uptime is the exposure operators actually own.
Reality
- Evidence78
- Adoption60
- Hype gap+12
- Incentives55
- Confidence74
Unit 42's three techniques all assume malware is already running on the box. That makes this an endpoint and browser-profile problem, not a reason to stall a passkey deployment.
Reality
- Evidence44
- Adoption24
- Hype gap+12
- Incentives41
- Confidence42