Google released Chrome 152 to the stable channel for Android, ChromeOS, Linux, macOS, and Windows, adding Connection Allowlists, the CPU Performance API, and a bypassable suspicious-site warning for Safe Browsing Enhanced Protection users. The warning appears when Chrome detects signals that a visited site may be malicious, while the release also expands support for CSSPseudoElement APIs and introduces web-platform, PWA, networking, media, and WebGPU changes.
Connection Allowlists let sites use the Connection-Allowlist HTTP response header to restrict the URL patterns that documents and web workers can contact. Chrome blocks non-allowlisted subresource requests, redirects, WebSocket connections, and other covered network activity at the network layer, limiting data-exfiltration opportunities from compromised third-party scripts, vulnerable dependencies, and untrusted generated code. The control complements, rather than replaces, Content Security Policy; it follows an origin trial that initially covered document contexts and did not support dedicated, shared, or service workers.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Google released Chrome 152 to the stable channel for Android, ChromeOS, Linux, macOS, and Windows. The release shipped Connection Allowlists for restricting document and worker network endpoints, introduced the CPU Performance API, and added bypassable suspicious-site warnings for Safe Browsing Enhanced Protection users.
Chrome announced an origin trial for Connection Allowlists, a deny-by-default HTTP-header mechanism that blocks network connections not matching a site's permitted URL patterns. The trial was scheduled for Chrome 148 through 151, initially supporting document contexts only.
Google Chrome published an early, unapproved proposal for a CPU Performance API exposing a coarse static CPU-performance tier through navigator.cpuPerformance. The proposal defines broad performance buckets and HTTPS-only access to limit fingerprinting, while positioning Compute Pressure as the complementary dynamic-load API.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
developer.chrome.com
Open sourcedeveloper.chrome.com
Open sourcegithub.com
Open sourcedeveloper.mozilla.org
Open sourcedeveloper.chrome.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.