TODAY , two critical exploits were detected: CVE-2026-82078 (PaperCut NG/MF Unsafe Reflection Vulnerability) and CVE-2026-81578 (Missing Authentication for Critical Function Vulnerability). Additionally, Google has completed the removal of all extensions based on the Manifest V2 protocol from the Chrome Web Store, marking the conclusion of the migration to the MV3 ecosystem. Users can no longer search for, download, or install these legacy extensions, and developers cannot push updates.
Users requiring legacy extensions are advised to monitor developer websites for manual updates, although relying on outdated versions poses security risks.