---
title: "Rebane: \"back in 2022 i found a bug tha…\""
url: https://daily.dev/posts/rebane-back-in-2022-i-found-a-bug-tha--op3lghfl7
source_url: https://infosec.exchange/@rebane2001/116606719764376414
type: article
source: "Lobsters"
published: 2026-05-21T01:23:51.445Z
updated: 2026-05-21T01:24:23.041Z
tags: ["security", "javascript", "chromium"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rebane: "back in 2022 i found a bug tha…"

**[Lobsters](https://daily.dev/sources/lobsters)** · 5 min read · 0 upvotes · 0 comments

## Summary

A security researcher discloses a Chromium browser bug discovered in 2022 that allows silently turning any Chromium-based browser into a persistent JavaScript botnet member with zero user interaction. The exploit works by visiting a single website and, in Microsoft Edge, persists even after closing the browser window due to Edge's background process behavior. The bug leverages service workers and took nearly 4 years to be addressed. Affected browsers include Edge, Brave, Opera, Vivaldi, and Arc. The bug report was briefly made public before being set to private again, with questions remaining about whether it is fully patched. Mitigations include disabling service workers via uBlock Origin CSP filters or NoScript.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://infosec.exchange/@rebane2001/116606719764376414>

---

Tags: [#security](https://daily.dev/tags/security), [#javascript](https://daily.dev/tags/javascript), [#chromium](https://daily.dev/tags/chromium)

[View this post on daily.dev](https://daily.dev/posts/rebane-back-in-2022-i-found-a-bug-tha--op3lghfl7)
