Threat Brief — 2026-07-25 — Chromium memory bugs, bridge drains again
Four Chromium memory-safety CVEs dropped in a single batch — three use-after-frees and one out-of-bounds write — all inherited by Microsoft Edge. Separately, the Wanchain cross-chain bridge between Binance and Cardano was exploited for roughly $10M (290M tokens) due to outdated architecture. The Chick-fil-A account compromise story continues to develop, with new reporting confirming the breach spread across multiple US states.
Top items
- Four Chromium memory-safety CVEs (CVE-2026-16804/16805/16806/16807) — Three use-after-free flaws in Input, Blink, and WebMCP plus an out-of-bounds write in Codecs. All are inherited by Microsoft Edge (Chromium-based). Browser memory bugs are prime candidates for drive-by exploitation; patch Chromium/Edge immediately. No public exploit evidence in the findings. (src: MSRC) · (src: MSRC) · (src: MSRC) · (src: MSRC)
- Wanchain Binance–Cardano bridge drained for ~$10M / 290M tokens — Attackers exploited outdated Wanchain architecture to steal approximately 290 million tokens in a single-day heist. This is a distinct incident from the Verus bridge losses reported on 2026-07-24 (first reported by RSS:xakep), underscoring a persistent pattern of cross-chain bridge vulnerabilities. *(src: SecurityLab)
- Chick-fil-A breach scope expands across multiple US states — Continuing development of the credential-stuffing attack first reported 2026-07-24 (first reported by RSS:bleepingcomputer-main). New reporting from SecurityLab confirms the account compromise hit thousands of customers across several US states. *(src: SecurityLab)
Themes
Bridge exploits remain the DeFi attack du jour — Two separate cross-chain bridge compromises in two days (Verus on 2026-07-24, Wanchain today) signal that legacy bridge architecture is a systemic weak point. Teams holding or transacting cross-chain assets should audit bridge dependencies and minimise hot-wallet exposure.
Browser patch hygiene — A quartet of Chromium memory-safety bugs hitting simultaneously reinforces the need for aggressive browser auto-update policies. Edge inherits all four; third-party Chromium-based browsers (Brave, Vivaldi, Arc) likely do as well.
