Leak of unfixed Chromium bug enables JavaScript after browser close

1 min read
Source: BleepingComputer
Leak of unfixed Chromium bug enables JavaScript after browser close
Photo: BleepingComputer
TL;DR

Google unintentionally exposed details of an unfixed Chromium vulnerability that can let a Service Worker keep executing JavaScript after the browser is closed, enabling remote code execution and potential botnet-like abuse across all Chromium-based browsers. Despite reports of a fix, researchers found the issue still exploitable in some builds, prompting urgent patching efforts and highlighting that attackers could exploit it with minimal user interaction; Google awarded a bug bounty, and the disclosure raised broad risk though it doesn’t grant access to emails or the host OS.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer