Bleepingcomputer Google Exposes Unfixed Chromium Flaw Allowing Remote Code Execution
Article Content
- •A critical unfixed vulnerability in Chromium allows remote code execution.
- •The flaw affects all Chromium-based browsers, including Chrome and Edge.
- •The issue remains exploitable despite being marked as fixed earlier this year.
Google has inadvertently revealed details of an unfixed vulnerability in Chromium that allows JavaScript to run in the background even after the browser is closed, enabling remote code execution (RCE) on affected devices. This flaw, reported by researcher Lyra Rebane in December 2022, affects all Chromium-based browsers, including Chrome, Edge, and Opera. Attackers can exploit this vulnerability by creating malicious web pages that utilize Service Workers, potentially leading to the formation of a botnet without user awareness. The issue was marked as fixed in February 2026, but subsequent testing revealed that the flaw persists in Chrome Dev and Edge versions. On May 20, 2026, access restrictions on the Chromium Issue Tracker were lifted, exposing the vulnerability details. The researcher confirmed that the exploit remains functional and is now even stealthier, as it no longer triggers a download prompt in Edge. Although the issue was made private again, the exposure of this information raises significant security concerns.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…