Researchers Uncover Critical Chromium Engine Flaw That Can Drain Memory and Trigger System Crash in 30 Seconds
3 week ago / Read about 0 minute
Author:小编   

Developed by Google, the Chromium engine forms the fundamental core for a wide array of browsers. However, researchers have recently unearthed a new vulnerability, dubbed "Brash," within its Blink rendering engine. This vulnerability takes advantage of a design oversight—specifically, the absence of rate - limiting for updates made through the document.title API. Malicious actors can exploit this by injecting millions of title changes every second. This onslaught of changes overloads the main thread, causing all browsers based on Chromium to crash within a mere 15 - 60 seconds. This security loophole impacts nine different browsers, including well - known ones like Chrome and Edge. Given their widespread use, it has the potential to affect over 3 billion users globally. The vulnerability is present in Chromium versions 143.0.7483.0 and earlier. It poses an especially grave threat to enterprise automation systems. Such systems could face significant disruptions, including interruptions to AIAgent operations, trading systems, and operational monitoring processes.