
On Wednesday, Google made headlines by releasing exploit code for a critical vulnerability in the Chromium browser framework, endangering millions of users worldwide. This flaw affects not only Google Chrome but also Microsoft Edge and a multitude of other browsers built on the Chromium platform. The published proof-of-concept code takes advantage of the Browser Fetch API, which is designed for downloading large files like videos in the background. Cybercriminals can leverage this exploit to monitor user behavior within their browsers and even act as a proxy for accessing websites or launching denial-of-service attacks. Alarmingly, the exploit can maintain connections even after the browser or the device has been restarted, leaving users vulnerable. Any website visited by a user can potentially exploit this vulnerability, creating a limited backdoor that could integrate devices into a small-scale botnet. While the capabilities of such an exploit are restricted to browser-like actions—such as visiting harmful sites or facilitating anonymous proxy browsing—the potential for abuse is significant. An attacker could potentially gather thousands, if not millions, of devices, setting the stage for future exploitation once an additional vulnerability is discovered. Lyra Rebane, the independent researcher who initially uncovered this vulnerability and alerted Google in late 2022, highlighted the seriousness of the situation. In an interview, Rebane noted, "The dangerous part here is that you can just have a lot of different browsers together that you can in the future run something on that you figure out." He emphasized that while using the exploit code is relatively straightforward, coordinating a large number of devices into a single network would require more effort. The vulnerability was classified as S1, the second-highest severity level, and remained under wraps for 29 months, known only to Chromium developers. On Wednesday morning, the information was finally made accessible via the Chromium bug tracker. Initially, Rebane thought the issue had been resolved, only to discover soon after that it remains unaddressed. Although Google has since removed the post, the exploit code can still be found on archival sites, raising further concerns about its accessibility to malicious actors.
In recent years, the AI sector has been intensely focused on identifying the most advanced models. While this pursuit re...
Business Insider | Jul 25, 2026, 13:10In a dramatic turn of events within the AI landscape, Hugging Face faced a significant security breach involving an AI a...
Business Insider | Jul 25, 2026, 20:30As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...
Business Insider | Jul 26, 2026, 10:10In a groundbreaking move to address the critical issue of renewable energy intermittency, a small town in southern Finla...
CNBC | Jul 25, 2026, 05:35
This past week has been challenging for the stock market, driven by several significant forces that have created turbule...
CNBC | Jul 25, 2026, 20:05