tech
Google publishes exploit code threatening millions of Chromium users
Google publishes exploit code before patch, reported 42 months earlier, is fixed.

TL;DR
- Google published exploit code for an unfixed vulnerability in the Chromium browser's Fetch API.
- The vulnerability, reported 46 months ago, allows attackers to monitor user activity and create a limited botnet.
- Exploitation is relatively easy but scaling it to large numbers of devices requires more effort.
- Google's premature publication means the exploit code is still available, despite the company removing its public post.
- Users of Chromium-based browsers like Chrome, Edge, Brave, Opera, Vivaldi, and Arc are at risk.
- Firefox and Safari are unaffected as they do not support the browser-fetching feature.
- Long delays in patching vulnerabilities are common for Google, but this is the longest reported case.
- The vulnerability is considered serious but does not allow attackers to access sensitive data like emails or the computer itself.