Google publishes exploit code threatening millions of Chromium users

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Google accidentally published proof-of-concept exploit code for an unpatched vulnerability in Chromium that was first reported 29 months ago. The flaw abuses the Browser Fetch API to turn any visiting browser into part of a limited botnet, enabling proxied DDoS attacks, anonymous browsing, and user activity monitoring. The exploit affects Chrome, Microsoft Edge, and all Chromium-based browsers. Although Google removed the post, it remains accessible via archival sites. The vulnerability was rated S1 (second-highest severity) by Chromium developers, yet remains unpatched.

2m read timeFrom arstechnica.com
Post cover image
Table of contents
Ars VideoHow Lighting Design In The Callisto Protocol Elevates The Horror
1 Comment

Sort: