tech

Google publishes exploit code threatening millions of Chromium users

Google publishes exploit code before patch, reported 42 months earlier, is fixed.

Google publishes exploit code threatening millions of Chromium users

TL;DR

  • Google published exploit code for an unfixed vulnerability in the Chromium browser's Fetch API.
  • The vulnerability, reported 46 months ago, allows attackers to monitor user activity and create a limited botnet.
  • Exploitation is relatively easy but scaling it to large numbers of devices requires more effort.
  • Google's premature publication means the exploit code is still available, despite the company removing its public post.
  • Users of Chromium-based browsers like Chrome, Edge, Brave, Opera, Vivaldi, and Arc are at risk.
  • Firefox and Safari are unaffected as they do not support the browser-fetching feature.
  • Long delays in patching vulnerabilities are common for Google, but this is the longest reported case.
  • The vulnerability is considered serious but does not allow attackers to access sensitive data like emails or the computer itself.