Millions of Chrome and Edge Users Exposed To Alarming Exploit by Google Security Blunder
Chromium, the base upon which Google Chrome and several other browsers including Microsoft Edge, Opera, and Vivaldi, is under attack. Sadly, the attack may have been avoidable, but since Google accidentally publicly posted proof of concept exploit code that was meant to remain private to Chromium developers, attackers can now use the exploit against virtually any Chromium-based browser.
This Chromium exploit utilizes malicious JavaScript code and a gap within Chromium's Fetch UI that allows remote monitoring and control of the user's browser and lays the groundwork for further exploitation, should a compatible vulnerability appear. Infected devices can then be utilized as a botnet, allowing average victims' devices and browsers to be used for purposes such as DDoS attacks or routing illegal web traffic.
Per Ars Technica's interview with Lyra Rebane, the researcher who discovered the exploit, using the exploit code published by Google would be "pretty easy" even...
Copyright of this story solely belongs to hothardware.com. To see the full text click HERE