Fake browser update
In plain terms
A banner in the middle of a page announces your browser is outdated and offers to update it. The downloaded file isn't an update: it's a program chosen by the attacker, and you're the one installing it.
Definition
A fake update is a web page that imitates a browser or system notification to get a malicious program downloaded and run, presented as an essential update.
How it works
While browsing an ordinary site — often a legitimate site whose ad network has been hijacked — a banner appears, reproducing the exact look of a browser notification: logo, typography, wording. It announces an outdated version and offers an update button. The downloaded file is a program, not an update, and the installation is entirely voluntary on the victim's part: that's what lets the attack bypass the browser's protections, which aren't broken through but sidestepped by the user themselves. Some variants ask you to copy a command and paste it into a system tool, which produces the same result with no visible download at all.
Warning signs
- Update notification displayed inside a web page rather than in the browser itself
- Executable file offered to "update" a piece of software
- Request to copy and paste a command into a terminal or execution window
- Update offered for a piece of software you don't use
- Page that prevents closing the tab or reappears automatically
How to verify
A browser updates itself and reports its status in its own menu, never in a page. Close the tab, then open the browser's menu and check the version there: it's the only place that counts. No legitimate update ever asks you to paste a command.
What to do
Don't run the downloaded file and delete it. Don't paste any command provided by a web page, whatever justification is given.
If it already happened
Disconnect the device from the network and have it scanned with an up-to-date security tool. From another healthy device, change the passwords of sensitive accounts starting with email, and enable two-factor authentication. Report the incident to the relevant authority.
Frequently asked questions
- The site I was on is a well-known, serious site though.
- That's common: the banner usually comes from an advertising slot loaded by the site, not from the site itself. How serious the visited site is says nothing about the content shown in its ads.
- I downloaded the file without opening it — am I exposed?
- A file that's downloaded but never run doesn't activate on its own. Delete it from the downloads folder, empty the trash, and run a security scan as a precaution.
Related attacks
Official sources
This article is part of the Website and browser attacks family. Last updated: 2026-08-31.