Google accidentally exposed details of unfixed Chromium flaw
… The flaw was reported by security researcher Lyra Rebane and acknowledged as valid in December 2022, as per the thread on Chromium Issue Tracker. …
… The flaw was reported by security researcher Lyra Rebane and acknowledged as valid in December 2022, as per the thread on Chromium Issue Tracker. …
… Yet despite that classification, the bug appears to have lingered in Chromium’s bug tracker for roughly 29 months without a fix reaching users. Rebane, who has previously reported Chrome security issues, says slow responses are unfortunately common. …
… The byte numbers are what is transmitted over the wire, and so they include the leaf certificate but not the root certificate. ↩ POSTED IN: Related stories Chromium Bringing a clearer, more consistent HDR video experience to Chrome Mixing High Dynamic Range HDR and standard video on the same screen… …
… In the Chrome Releases blog post, Srinivas Sista lists the 26 security vulnerabilities that have been fixed. They were predominantly discovered by external security researchers and reported to Google. …
… And while Google is at least somewhat aware of the issue—the latest removal might be following a weekend Reddit post— its enforcement of security seems to be reactionary rather than proactive. …
… While speaking to Android Authority , a Google spokesperson commented on the issue: Interestingly, the large file does seemingly come with a "warning" that Chrome will download it, suggesting that the browser may have been granted permission to download any files it requires to function. …
… According to Hanff, the behavior mirrors a separate issue he recently identified involving Anthropic's desktop software, and together the two cases point to a broader pattern of how large tech companies deploy AI features. …
… Because of that, especially when security is part of the equation, Chrome still wins. …
… The company later said the removal was temporary, and based on early feedback and technical evaluation, not a cancellation or security issue. …
… More importantly, you can still use Chrome or Chromium if you want. …