New 'Brash' vulnerability crashes Chromium browsers with a single URL.
A newly disclosed vulnerability, codenamed “Brash,” in the Blink rendering engine of Chromium-based browsers could lead to their instant crashes when exploited through a malicious URL. Security researcher Jose Pino explained that the flaw allows attackers to efficiently bombard browsers with excessive document.title updates, overwhelming the main thread and causing unresponsiveness. This exploit can be programmed to activate at precise moments, functioning akin to a logic bomb that operates undetected until triggered. The vulnerability affects major browsers including Google Chrome and Microsoft Edge, while Mozilla Firefox and Apple Safari remain unaffected. The significance of this flaw underscores the urgent need for improved security measures in widely used web technologies to protect users from sophisticated cyber threats.
