logo

Google’s Exploit Code Release Raises Concern Over Unfixed Chromium Security Bug

ID: df3a4530-3887-588a-a26a-bb32aa5f6136

STIX ID: report--df3a4530-3887-588a-a26a-bb32aa5f6136

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Divya

...
...

Google published proof-of-concept exploit code for a high-risk, unpatched Chromium Browser Fetch API flaw first reported in 2022. The vulnerability allows attackers to register Service Workers that initiate indefinite background fetches, enabling persistent communication with attacker-controlled C2 servers and effectively turning infected Chromium-based browsers (Chrome, Edge, Brave, Opera) into lightweight botnet nodes. The issue is tracked as Priority 1/Severity 2 internally, can require no user interaction beyond visiting a malicious site, may persist across restarts in some implementations, and has broad impact potential given the scale of Chromium users; the report urges disabling Service Worker/background fetch features via policy, monitoring outbound browser traffic, and using isolation until a patch is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.