Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
2026-04-11T19:24:11Z•0581da4a7db68bb4e18e9e6fdef6aed85dc767c485a2544583c1918a594ef104
AI-extensionsAndroid SDKCVE-2026-39987Chrome 146CobwebsDBSCEngageLab SDKGlassWormIDE compromiseLucidRookMarimoOpen VSXPenlinkRCESmart Slider 3 ProUAT-10362WeblocWordPressZig dropperbackdoorbrowser-extensionscrypto-walletsgeolocationsupply-chainsurveillance
What happened
A broad set of high-risk threats and vulnerabilities was reported: law‑enforcement and police agencies reportedly used Cobwebs/Penlink’s Webloc ad‑based geolocation system to track hundreds of millions of devices; GlassWorm evolved with a Zig‑based dropper that infects developer IDEs via a malicious Open VSX extension; browser/AI extensions are highlighted as an under‑protected attack surface; and Google rolled out Device Bound Session Credentials (DBSC) in Chrome 146 for Windows. Multiple actively exploited and high‑impact vulnerabilities were disclosed or weaponized — notably Marimo RCE (CVE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0581da4a7db68bb4e18e9e6fdef6aed85dc767c485a2544583c1918a594ef104
- Enrichment time
- 2026-04-11T19:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.