Bleepingcomputer
Google Exposes Unfixed Chromium Flaw Allowing Remote Code Execution
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Google has inadvertently revealed details of an unfixed vulnerability in Chromium that allows JavaScript to run in the background even after the browser is closed, enabling remote code execution (RCE) on affected devices. This flaw, reported by researcher Lyra Rebane in December 2022, affects all Chromium-based browsers, including Chrome, Edge, and Opera. Attackers can exploit this vulnerability by creating malicious web pages that utilize Service Workers, potentially leading to the formation of a botnet without user awareness. The issue was marked as fixed in February 2026, but subsequent testing revealed that the flaw persists in Chrome Dev and Edge versions. On May 20, 2026, access restrictions on the Chromium Issue Tracker were lifted, exposing the vulnerability details. The researcher confirmed that the exploit remains functional and is now even stealthier, as it no longer triggers a download prompt in Edge. Although the issue was made private again, the exposure of this information raises significant security concerns.
Key Points: • A critical unfixed vulnerability in Chromium allows remote code execution. • The flaw affects all Chromium-based browsers, including Chrome and Edge. • The issue remains exploitable despite being marked as fixed earlier this year.