A critical vulnerability in the Blink rendering engine, affecting Chrome, Microsoft Edge, and other Chromium-based browsers, allows attackers to crash browsers within seconds by abusing the document.title API. Security researcher Jose Pino discovered the flaw, dubbed Brash, and published a proof-of-concept exploit after his responsible disclosure to Google went unanswered for two months. The exploit works by rapidly updating the document title millions of times per second, overwhelming the browser's main thread and causing a denial-of-service condition, with some tests even freezing the host system.
The vulnerability impacts at least nine major browsers across Android, macOS, Windows, and Linux, including Chrome, Edge, Opera, Vivaldi, and OpenAI's ChatGPT Atlas. With Chrome alone accounting for over three billion users, the scale of exposure is significant. Despite the public disclosure and demonstration of the exploit, Google and other affected vendors have not yet issued a patch or commented on the issue, raising concerns about their vulnerability response processes and the potential for widespread disruption until a fix is released.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting said the researcher published exploit details and attack methodology after Google had not yet issued a patch or responded. The write-up described a multi-phase attack flow and said the flaw affected Chromium-based browsers across major desktop platforms.
Security researcher Jose Pino disclosed a denial-of-service flaw dubbed 'Brash' in Chromium's Blink rendering engine. The issue abuses the document.title API to trigger massive DOM updates, causing CPU spikes, freezes, and browser crashes after a user visits a malicious URL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecsoonline.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.