Google Exposes Unfixed Chromium Flaw Allowing Remote Code Execution

Google Exposes Unfixed Chromium Flaw Allowing Remote Code Execution

First seen 21 May 2026, 20:04 UTC BleepingcomputerCsoonline 96% similarity 66.0

Article Content

Browse articles
ThreatCluster

Google has inadvertently revealed details of an unfixed vulnerability in Chromium that allows JavaScript to run in the background even after the browser is closed, enabling remote code execution (RCE) on affected devices. This flaw, reported by researcher Lyra Rebane in December 2022, affects all Chromium-based browsers, including Chrome, Edge, and Opera. Attackers can exploit this vulnerability by creating malicious web pages that utilize Service Workers, potentially leading to the formation of a botnet without user awareness. The issue was marked as fixed in February 2026, but subsequent testing revealed that the flaw persists in Chrome Dev and Edge versions. On May 20, 2026, access restrictions on the Chromium Issue Tracker were lifted, exposing the vulnerability details. The researcher confirmed that the exploit remains functional and is now even stealthier, as it no longer triggers a download prompt in Edge. Although the issue was made private again, the exposure of this information raises significant security concerns.

Key Points: • A critical unfixed vulnerability in Chromium allows remote code execution. • The flaw affects all Chromium-based browsers, including Chrome and Edge. • The issue remains exploitable despite being marked as fixed earlier this year.

ThreatCluster AI

Timeline

2022-12-01
Vulnerability reported by Lyra Rebane
Rebane reported a flaw in Chromium that allows JavaScript to run in the background, enabling RCE.
Bleepingcomputer
2024-10-26
Google developer flags the issue
A Google developer noted the vulnerability was still open and required a status update due to its severity.
Bleepingcomputer
2026-02-10
Issue marked as fixed
The vulnerability was marked as fixed but reopened shortly after due to concerns about the patch.
Bleepingcomputer
2026-02-12
Bug bounty awarded
Rebane received a $1,000 bug bounty for reporting the vulnerability, despite the patch not being shipped.
Bleepingcomputer
2026-05-20
Access restrictions lifted
All access restrictions on the Chromium Issue Tracker were removed, exposing the vulnerability details.
Bleepingcomputer
2026-05-21
Rebane confirms exploit still works
Rebane tested the fix and confirmed the vulnerability persists, allowing silent RCE without user interaction.
Bleepingcomputer

Community

Browse all →