Chromium publishes fixed exploit 4 years later, turns out it's actually unfixed
Summary
A security exploit in Chromium, thought to have been fixed four years ago, was found to actually remain unfixed, highlighting a significant oversight in the browser's security patching process.
Similar Articles
Google publishes exploit code threatening millions of Chromium users
Google published exploit code for an unfixed Chromium vulnerability that can turn browsers into a limited botnet, affecting Chrome, Edge, and other Chromium-based browsers. The vulnerability remains unpatched after 29 months.
4 groups caught using the same Chrome and Windows exploit kit
An exploit kit named BlueMoon, targeting critical vulnerabilities in Chromium browsers and Windows, has been used by at least four hacking groups, some with ties to the Chinese government. Researchers from Proofpoint reported rapid deployment and sharing of the kit, possibly aided by AI, within a patch gap in the Chromium supply chain.
Chrome team ships the most ever security vulnerability fixes in a release - after another record last month
Google Chrome fixed a record 429 security flaws in one update, with only a quarter coming from external researchers, aided by Mythos-capable models for automated vulnerability discovery and patching.
Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307
A single vulnerability in Chrome's V8 JIT compiler, CVE-2026-6307, allows attackers to gain arbitrary read/write primitives within the V8 sandbox and escape it to achieve remote code execution, affecting Chrome versions since 106.
Google fixed more Chrome bugs in June than over the past two years, thanks to AI
Google is using AI and LLMs to automate Chrome vulnerability discovery, triage, and patching, resulting in more bugs fixed in June than in the past two years, including a 13-year-old sandbox escape.