Google publishes exploit code threatening millions of Chromium users - Ars Technica
Google published proof-of-concept exploit code for an unfixed vulnerability in the Browser Fetch API affecting Chrome, Edge, and all Chromium-based browsers — code that lets an attacker monitor browsing activity and use targeted browsers as proxies. The flaw was reported in late 2022 by independent researcher Lyra Rebane and rated S1 severity internally, yet remains unpatched.