logo

Google publishes exploit code threatening millions of Chromium users

ID: ee946665-8335-5eb8-854b-b81d2de2df2a

STIX ID: report--ee946665-8335-5eb8-854b-b81d2de2df2a

Feed Name: Security - Ars Technica

Threat Score
45/100

Date Published: 2026-05-20

Date Updated: 2026-05-22

Author: Dan Goodin

...
...

A reported Chromium vulnerability allows attackers to misuse the Background Fetch/service worker APIs so a malicious site can launch a persistently active service worker and stealthy downloads; the issue affects Chrome and other Chromium-based browsers (Brave, Opera, Vivaldi, Arc), while Firefox and Safari are not vulnerable. The researcher reported long delays in patching, Google acknowledged the code publication and is working on a fix, and developers indicate limited observed use of the background fetch feature with no clear evidence of large-scale exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.