HomeSecurityGoogle exposed details of unpatched Chromium vulnerability

Google exposed details of unpatched Chromium vulnerability

A particularly worrying incident in the cybersecurity world has been brought to the fore by Google, after it inadvertently leaked information about a serious and apparently still active security flaw in Chromium. The issue affects browsers based on Google's popular engine, such as Chrome and Microsoft Edge, and could allow malicious JavaScript code even after the user has closed the browser.

Google Chrome

The case has caused intense concern in the security community, as the exploit is characterized as particularly insidious and difficult to detect by the average user.

How the dangerous exploit works

The vulnerability was discovered by security researcher Lyra Rebane, who reported the issue on the Chromium Issue Tracker back in 2022. According to the information released, the bug is related to the operation of Service Workers, a technology that allows web applications to run processes in the background.

See also: Google Chrome update fixes 79 security vulnerabilities

An attacker could create a malicious website that triggers a Service Worker that never terminates. This means that JavaScript can continue to run on the victim's device even after the browser is closed.

In practice, this technique could be used to create a stealth botnet based solely on JavaScript, without requiring the installation of traditional malware or user interaction beyond a simple visit to a website.

The problem remains active despite the "fix"

What makes the case even more serious is the fact that the bug was officially considered fixed by Google. Access restrictions on the Issue Tracker were removed on May 20th, as the bug had been marked as resolved for more than 14 weeks.

However, when Rebane retested the exploit in the newer developer builds of Chrome Dev 150 and Edge 148, she found that the vulnerability continued to function normally.

See also: Chrome consumes 4GB of space with Gemini Nano AI model

Google exposed details of unpatched Chromium vulnerability

She even stated that the exploit not only remains active, but in some cases has become even more “silent” and dangerous. In the latest versions of Edge, for example, the download pop-up that previously served as an indication that suspicious activity was taking place no longer appears.

This means that a user could theoretically visit a malicious page and then continue using their computer normally without realizing that a connection to a remote control server remains active.

Why Chromium is such a critical target

Chromium is the basis for most modern browsers, including Google Chrome, Microsoft Edge, Opera, Brave, and others. This turns any serious vulnerability in the platform into a potential threat to hundreds of millions of users worldwide.

Service Workers were originally created to improve the user experience of web applications by enabling features such as offline access, push notifications, and background data synchronization. However, when such technology is combined with process management errors, it can become a powerful cyberattack tool.

Security experts point out that browser-based attacks have become increasingly popular in recent years because they do not require the installation of executable files, making them significantly more difficult to detect by antivirus and traditional security systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: 108 malicious Chrome extensions steal Google and Telegram data

What users can do

Although this vulnerability does not allow full access to the operating system, nor does it allow for the theft of files or emails outside the browser sandbox, it remains particularly dangerous due to the possibility of execution JavaScript.

Google exposed details of unpatched Chromium vulnerability

Rebane clarified that the exploit does not bypass the browser's security boundaries, but it can be used to monitor activity, communicate with command-and-control servers, or participate in DoS attacks.

Until there is an official and confirmed effective fix, experts recommend that users keep browsers, avoid unknown websites, and disable unnecessary background permissions where possible.

Google is now under pressure

The inadvertent release of the exploit details significantly increases the pressure on Google to address the issue immediately. Although the report was made private again shortly after, the information had already leaked to the security community and researchers.

This increases the risk of proof-of-concept attacks or even mass exploitation of the vulnerability before a full security patch.

So far, Google has not issued an official statement on the incident, while the cybersecurity community is closely monitoring developments surrounding one of the most worrying browser exploits in recent years.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS