Google publicly released proof-of-concept exploit code for a long-unfixed Chromium vulnerability in the Browser Fetch API, exposing Chrome, Microsoft Edge, Brave, Opera, and other Chromium-based browsers to abuse by any malicious website a user visits. Researcher Lyra Rebane reported the flaw in late 2022, but it remained unresolved for years despite being internally classified as serious. The bug lets an attacker register a Service Worker and create a background fetch task that can persist as a covert communication channel, enabling browser monitoring, anonymous proxying, traffic redirection, and potential browser-based botnets; some implementations reportedly keep the connection alive even after the browser closes or the device reboots.
At the same time, Google issued Chrome Stable Channel updates for versions before 148.0.7778.178/179, and government and vulnerability trackers highlighted multiple newly disclosed flaws fixed in that release. Those included CVE-2026-9120, a high-severity WebRTC use-after-free that could allow remote code execution in the browser sandbox via a crafted HTML page; CVE-2026-9126, a DOM use-after-free with similar impact; and CVE-2026-9121, a GPU out-of-bounds read that could lead to heap corruption. The contrast between patched Chrome memory-corruption bugs and the still-unfixed Browser Fetch issue raised concern because the published exploit code lowers the barrier to abuse across millions of Chromium users, prompting recommendations to restrict Service Worker use, disable background fetch where possible, monitor outbound browser traffic, and consider browser isolation in enterprise environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Google publicly released proof-of-concept exploit code for an unfixed Chromium Browser Fetch API vulnerability in May 2026. The disclosure exposed a flaw affecting Chrome, Edge, and other Chromium-based browsers that could be abused for persistent communications, proxying, botnet activity, and denial-of-service operations.
Independent researcher Lyra Rebane privately reported a Browser Fetch API vulnerability in Chromium to Google in late 2022. The flaw could let malicious sites create persistent background connections for monitoring, proxying, or denial-of-service activity.
CVE-2026-9126 was recorded on May 20, 2026 as a use-after-free flaw in Chrome's DOM component. The issue affects versions prior to 148.0.7778.179 and could allow arbitrary code execution inside the browser sandbox through a crafted HTML page.
CVE-2026-9121 was recorded on May 20, 2026 for an out-of-bounds read in Chrome's GPU component affecting versions prior to 148.0.7778.179. Successful exploitation via a crafted HTML page could potentially lead to heap corruption.
CVE-2026-9120 was disclosed on May 20, 2026 as a high-severity use-after-free vulnerability in Chrome's WebRTC component. It affects Chrome versions prior to 148.0.7778.179 and could allow remote code execution via a crafted HTML page.
Google published a security advisory on May 19, 2026 for Chrome Stable Channel Desktop releases. The advisory addressed vulnerabilities affecting versions prior to 148.0.7778.178/179 on Windows and Mac and prior to 148.0.7778.178 on Linux.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcearstechnica.com
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.