New Exploit Can Crash Chromium Browsers Worldwide
A new exploit called Brash can crash Chromium browsers in seconds by overloading the tab title API.
A newly discovered exploit, known as Brash, has exposed a critical architectural weakness in Chromium’s Blink rendering engine, allowing attackers to crash browsers like Google Chrome, Microsoft Edge, Opera, Brave, and others within seconds.
The vulnerability, disclosed by security researcher Jose Pino (Jofpin), represents a disruptive flaw in modern browser architecture, capable of rendering entire systems unresponsive with nothing more than a single malicious URL.
The Brash exploit leverages the absence of rate limiting on the document.title API, which controls browser tab titles.
The flaw does not rely on privilege escalation or memory corruption — making it easy to reproduce and difficult to mitigate without changes to the browser’s core architecture.
Pino’s research indicates that the attack can collapse any Chromium-based browser within 15 to 60 seconds, depending on system performance and configuration.
The exploit consumes massive CPU resources during execution, degrading system performance and freezing concurrent processes.
The Brash exploit operates in three primary stages that sequentially increase system load until failure:
This attack sequence is not only efficient but also highly tunable.
The exploit can be configured to activate at specific moments using temporal triggers, allowing attackers to program “logic bombs” that detonate at predetermined times.
The Brash vulnerability affects all browsers built on the Chromium framework — including Chrome, Edge, Opera, Vivaldi, Brave, Arc Browser, Dia Browser, Perplexity Comet, and ChatGPT Atlas.
Testing has shown that browsers on macOS, Windows, and Linux crash within seconds when exposed to the exploit.
The impact is significant because Chromium underpins the majority of web browsers, which potentially impacts billions of users.
The following table summarizes crash times across browsers tested by the researcher browsers:
Notably, browsers using non-Chromium engines — such as Mozilla Firefox (Gecko) and Apple Safari (WebKit) are protected from this specific attack.
All browsers on iOS also remain unaffected, as Apple mandates WebKit usage for third-party browsers on the platform.
While the Brash exploit requires only a website visit to execute, its potential for harm extends far beyond browser crashes.
In more targeted applications, Brash could be embedded within scripts used by AI-driven automation tools or headless browsers employed in web scraping and compliance verification.
At the time of the researcher’s disclosure, Google had not yet issued an official response.
Pino emphasized that Brash is not a traditional software bug but a design oversight — a failure to implement rate throttling within a critical API.
Because the exploit exploits normal browser behavior rather than security flaws, traditional antivirus tools and sandboxing are potentially ineffective. Organizations can take the following steps:
Combining strong technical safeguards with informed users helps organizations limit exposure to browser-based threats. A layered defense strategy ensures resilience even when individual controls are bypassed.
The Brash exploit highlights a growing challenge in modern browser security: as web technologies evolve, even legitimate APIs can be turned into attack vectors.
It reveals how underlying architectural assumptions user behavior and system trust can create blind spots that traditional defenses fail to catch.
Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.
Cybercriminals are turning AdaptixC2, an open-source security tool, into a weapon for ransomware attacks.
Chinese-linked group UNC6384 targets European diplomats with a Windows shortcut exploit to deploy PlugX malware.
Hidden npm malware steals developer credentials, exposing major software supply chain risks in the open-source ecosystem.
Hackers breached Canadian water, energy, and farm systems, prompting national warnings to secure industrial control networks.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
