Google publishes exploit code threatening millions of Chromium users



Google on Wednesday published exploit code for an unfixed vulnerability in its Chromium browser codebase that threatens millions of people using Chrome, Microsoft Edge, and virtually all other Chromium-based browsers.

The proof-of-concept code exploits the Browser Fetch programming interface, a standard that allows long videos and other large files to be downloaded in the background. An attacker can use the exploit to create a connection for monitoring some aspects of a user’s browser usage and as a proxy for viewing sites and launching denial-of-service attacks. Depending on the browser, the connections either reopen or remain open even after it or the device running it has rebooted.

Unfixed for 29 months (and counting)

The unfixed vulnerability can be exploited by any website a user visits. In effect, a compromise amounts to a limited backdoor that makes a device part of a limited botnet. The capabilities are limited to the same things a browser can do, such as visit malicious sites, provide anonymous proxy browsing by others, enable proxied DDoS attacks, and monitor user activity. Nonetheless, the exploit could allow an attacker to wrangle thousands, possibly millions, of devices into a network. Once a separate vulnerability becomes available, the attacker could use it to then compromise all those devices.

“The dangerous part here is that you can just have a lot of different browsers together that you can in the future run something on that you figure out,” said Lyra Rebane, the independent researcher who discovered the vulnerability and privately reported it to Google in late 2022 in an interview. She said using the exploit code Google prematurely published would be “pretty easy,” although scaling it to wrangle large numbers of devices into a single network would require more work. In the thread of Rebane’s disclosure to Google, two developers said in separate responses that it was a “serious vulnerability.” Its severity was rated S1, the second-highest classification.

Since its reporting 29 months ago, the vulnerability remained unknown except to Chromium developers. Then on Wednesday morning, it was published to the Chromium bug tracker. Rebane initially assumed the vulnerability was finally fixed. Shortly thereafter, she learned that, in fact, it remained unpatched. While Google removed the post, it remains available on archival sites, along with the exploit code.



Source link

  • Related Posts

    ‘Fuck you, Bambu’: How one private message could change the face of 3D printing

    Bambu Lab makes the best, most accessible 3D printers yet, but that reputation is suddenly under siege. It all started when Paweł Jarczak received a private message from the company…

    Trump wants $1B to protect White House ballroom from drones and other threats

    President Donald Trump’s latest pitch for using taxpayer dollars to secure his White House ballroom featured a militarized building—including a rooftop hardened against drone strikes and a “drone port” that…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Gilgeous-Alexander scores 30 as Thunder even series in Game 2

    Gilgeous-Alexander scores 30 as Thunder even series in Game 2

    Bernie Sanders backs climate activist in close Michigan congressional primary | Michigan

    Bernie Sanders backs climate activist in close Michigan congressional primary | Michigan

    ‘Fuck you, Bambu’: How one private message could change the face of 3D printing

    ‘Fuck you, Bambu’: How one private message could change the face of 3D printing

    Poilievre to launch next phase in bid to pressure Liberals to ‘put private property first’

    Poilievre to launch next phase in bid to pressure Liberals to ‘put private property first’

    lululemon athletica inc. Announces First Quarter Fiscal 2026 Earnings Conference Call

    Mick Jagger to play Josh O’Connor’s father in new film from Alice Rohrwacher | Movies

    Mick Jagger to play Josh O’Connor’s father in new film from Alice Rohrwacher | Movies