Rebane: "back in 2022 i found a bug tha…"

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A security researcher discloses a Chromium browser bug discovered in 2022 that allows silently turning any Chromium-based browser into a persistent JavaScript botnet member with zero user interaction. The exploit works by visiting a single website and, in Microsoft Edge, persists even after closing the browser window due to Edge's background process behavior. The bug leverages service workers and took nearly 4 years to be addressed. Affected browsers include Edge, Brave, Opera, Vivaldi, and Arc. The bug report was briefly made public before being set to private again, with questions remaining about whether it is fully patched. Mitigations include disabling service workers via uBlock Origin CSP filters or NoScript.

5m read timeFrom infosec.exchange
Post cover image
481 Impressions