Topic

Google

🇷🇺Jul 22

DeepSeek User Conversations Appear in Google Search Results via Publicly Shared Links

Conversations between users and the Chinese AI service DeepSeek, including Russian-language exchanges, have surfaced in Google search results. The exposed pages belong to Shared Conversations that users themselves made public through shareable links. These pages display full question-and-answer histories along with the names of any uploaded documents. No actual breach of DeepSeek occurred, and security researchers note that search engines indexed similar public chatbot dialogues more than a year ago. MWS AI confirmed that no closed chat histories or account access were exposed. Meanwhile, Yandex stated that links to conversations with its Alice AI assistant are blocked from indexing, remain active for only 14 days, and do not transmit attached files to recipients.

AntiMalware•Privacy & Surveillance
🇵🇹Jul 21

EU Forces Google to Open Android Microphone, Camera and Screen Access for Rival AI Assistants

The European Union has ordered Google to provide competing AI assistants with the same level of access to sensitive Android resources that is currently reserved for Gemini. The ruling covers eleven system functions, including voice activation, home button integration, background execution, and on-device AI model access. Rival assistants will also gain real-time environmental data streams from the microphone, camera, screen, and speakers under identical consent and notification rules applied to Google services. Additional capabilities include cross-app interaction, messaging, scheduling, device settings control, and multi-step task automation. Screen automation will allow assistants to operate apps inside a virtual window while the user performs other activities. Most changes are scheduled for Android 18 by 1 August 2027, while simultaneous activation of multiple assistants by voice keyword will arrive in Android 19 no later than 1 August 2028. Access to the most sensitive functions may require objective security certification and explicit user authorization.

BoletimSec•Policy & Regulation
🇯🇵Jul 21

Google Issues Emergency Chrome Update Patching Seven Vulnerabilities Including Three Critical Flaws

Google has released a new security update for its Chrome browser addressing seven vulnerabilities just two days after the previous patch. The update covers Windows, macOS, and Linux platforms with versions Chrome 150.0.7871.129 and 150.0.7871.128. Three of the issues, tracked as CVE-2026-15899, CVE-2026-15900, and CVE-2026-15901, received the highest severity rating of Critical and involve Use After Free flaws in CameraCapture, GPU, and Network components. Four additional High-severity vulnerabilities were also fixed, including an out-of-bounds access issue in the V8 JavaScript engine and Use After Free problems in Cast, Ozone, and Aura. The company plans to roll out the patches gradually over the coming days and weeks to all users.

Security NEXT•Vulnerabilities & Exploits
🇷🇺Jul 20

Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud

Android users are discovering a new system application called Android Developer Verifier with the package identifier com.google.android.verifier that Google installs automatically through system updates without any separate consent prompt. The service prepares devices for upcoming restrictions on installing APK files from unknown sources by checking whether an app is registered to a verified developer who has passed identity verification and supplied legal information to Google. This verification does not guarantee an application is safe but allows Google to associate it with a specific individual or company, helping combat social-engineering scams in which fraudsters pressure victims into disabling protections and installing malicious APKs. To install software from an unverified developer, users will need to enable developer mode, confirm they are not under duress, reboot the device, wait 24 hours, and re-authenticate with PIN or biometrics. The new requirements begin on 30 September in Brazil, Indonesia, Singapore, and Thailand, with worldwide expansion planned for 2027 and later. While the app can currently be removed, it is unclear whether future updates will restore it, and advanced users retain the option to sideload via ADB, which bypasses the new checks entirely.

AntiMalware•Fraud & Social Engineering
🇷🇺Jul 17

VK Apps Remain Downloadable in US Google Play Despite Removal in Russia and Turkey Amid Sanctions

The removal of VK services from Google Play has proven to be less global than initially reported, with applications still accessible to users whose Google accounts are registered in the United States region. Testing revealed a clear geographic pattern: the apps are unavailable in Russian and Turkish storefronts but remain fully visible and installable under the American region. The services disappeared from the store on July 16, prompting VK to confirm that already installed applications will continue functioning without restrictions and directing users to alternative stores such as RuStore. The exact cause of the regional discrepancy remains unclear and may relate to Google Play configuration settings, ongoing sanctions against Russia, distribution policies, or simple catalog synchronization delays. In a related development, VK users have begun receiving notifications urging them to switch to the vk.ru domain, which the company states offers superior speed and reliability and will now serve as the primary address.

AntiMalware•Policy & Regulation
🇷🇺Jul 16

Google to Allow Competing Android App Stores Directly Inside Play Store After Epic Games Court Ruling

Google is preparing to open its official Google Play store to rival Android app marketplaces starting July 22, following a court order issued in the long-running antitrust lawsuit with Epic Games. The ruling stems from the 2020 Fortnite dispute over Google’s 30% commission and direct in-app purchases that bypassed the platform’s billing system. A federal judge determined that Google had unlawfully prevented device makers from promoting or pre-installing alternative app stores, thereby reinforcing Google Play’s monopoly position. As a result, approved third-party stores will now be distributed directly through Google Play, receive default access to its app catalog, and be subject to an annual $5,000 verification fee. Developers retain the right to block distribution of their apps on specific stores, while participating marketplaces must meet strict security, copyright, and update obligations or risk removal if suspicious installations exceed 1%. Although the changes are expected to apply primarily in the United States, the decision marks a fundamental shift in how Google must accommodate competitors within its own ecosystem.

AntiMalware•Policy & Regulation
🇷🇺Jul 15

Google Urges European Commission to Stop Mass Blocking of IP Addresses, DNS Services and VPNs in Piracy Fight

Google has called on the European Commission to abandon the widespread practice of blocking IP addresses, DNS services and VPNs as a means of combating pirate sites, describing the approach as both ineffective and risky. The company explained that such blocks fail to remove illegal content permanently and allow users to quickly switch to alternative DNS providers, VPNs or new addresses, enabling piracy to continue uninterrupted. Blocking entire IP ranges is particularly problematic because a single address or range is often shared by multiple unrelated legitimate websites and cloud services, leading to collateral damage for lawful users. Google cited the December 2019 incident in Portugal, where ISP blocks on virtual IP addresses disrupted important Google services and affected Google Cloud customers sharing the same infrastructure. A similar outcome followed the blocking of The Pirate Bay in the United Kingdom, after which lists of proxy servers rapidly appeared online to restore access. The search giant stressed that these measures only create temporary obstacles rather than eliminating the source of pirated material and increase the chance of accidentally disabling legitimate online resources.

securitylab_n•Policy & Regulation
🇷🇺Jul 14

Hidden Spy for 1.6 Million Users: Popular Browser Extension ModHeader Secretly Collected Browsing History

Google and Microsoft have removed the popular ModHeader browser extension from the Chrome Web Store and Microsoft Edge Add-ons after security researchers discovered a hidden mechanism designed to secretly collect users' browsing history. The extension, which had approximately 1.6 million installations, allowed developers to modify HTTP headers for testing and debugging purposes but contained a dormant data-collection module in its legitimate codebase. British firm Stripe OLT confirmed that the suspicious code was part of the genuine signed build rather than a fake version. Although the history-stealing functionality remained inactive due to an empty internal browser list, the extension still transmitted telemetry data and could have been activated remotely via a simple update. Experts recommend immediate removal of the extension, replacement of any credentials entered through it, and blocking of the domains stanfordstudies[.]com and extensions-hub[.]com.

securitylab_n•Other
🇷🇺Jul 14

Google Enhances Android Backup Controls in Play Services Update, Adds Document Sync to Google Drive Amid Storage Limit Cut

Google is updating its Android backup system through Google Play Services version 26.25, introducing separate toggles for messaging backups and the ability to automatically save documents to the cloud. Users can now disable SMS, MMS, and RCS backups independently, though RCS remains nested under the MMS category for less visibility. The new document backup feature supports formats including DOC, PPT, XLS, and PDF, storing copies in a device-named folder on Google Drive without automatic synchronization to the original files. These changes coincide with Google's reduction of free storage from 15 GB to 5 GB, where Android backups now count against the quota, potentially turning small 40 MB backups into much larger archives. The update provides more granular control over what gets backed up, including call history and system settings, accessible via Settings > Accounts and backup > Google Backup > Other device data. While the feature can help preserve important files, it risks quickly exhausting limited free storage if documents are included.

AntiMalware•Other