
Google accidentally published details about an unfixed Chromium vulnerability that can keep JavaScript running after the browser is closed, allowing remote code execution on affected devices. That accidental disclosure exposed implementation details that could speed exploit development before a patch is available. Microsoft’s public threat against a researcher who released exploit code underscores rising tensions over disclosure practices and suggests legal fallout may further complicate researchers’ willingness to publish findings that could help defenders but also enable attackers.
Click a connection line between nodes to view confidence and evidence.