Unpatched Chromium Vulnerability Exposed by Google Could Affect Millions of Browsers
Google recently published proof-of-concept exploit code for a critical, yet unpatched, vulnerability in its Chromium browser codebase. This security flaw impacts not only Google Chrome but also Microsoft Edge and nearly all other Chromium-based browsers. The vulnerability abuses the Browser Fetch API, which allows large files and long videos to download in the background. Exploit code can create persistent connections, monitor users’ browser activity, enable anonymous proxy access, and facilitate denial-of-service attacks. In some browsers, these connections persist even after a reboot, effectively creating a limited botnet from affected devices. The flaw was discovered by independent researcher Lyra Rebane in late 2022 and reported privately to Google. Despite a 29-month delay, the vulnerability remained unpatched when Google published the exploit code on the Chromium bug tracker, though it was later removed. However, the code remains accessible through archival sites. Security experts warn that while exploiting this vulnerability on a large scale requires additional work, the potential risk is significant. This incident highlights ongoing challenges in software patch management and the consequences of prematurely publishing sensitive exploit information.
