Security researcher Jose Pino has unveiled a critical vulnerability dubbed "Brash," impacting all browsers built upon Chromium kernel versions 143.0.7483.0 and earlier. This flaw has the potential to affect over 3 billion devices globally. The vulnerability arises from an inherent architectural defect within the Blink rendering engine, specifically during its handling of certain DOM (Document Object Model) operations. This defect enables attackers to freeze the browser interface and, in severe cases, lead to temporary system-wide paralysis.
To gauge their exposure to this risk, users can visit brash.run. It's important to note that browsers not utilizing the Chromium kernel remain unaffected by this vulnerability. At present, Jose Pino has made the technical specifics of the vulnerability publicly available. Relevant vendors are actively investigating the matter; however, no remedial patches or updated browser versions have been released as of yet.
