• News/
  • https://www.theregister.com/2025/10/29/brash_dos_attack_crashes_chromium/

Security hole slams Chromium browsers - no fix yet

The Register
·
Jessica Lyons
·
Published Oct 29, 2025
·
Updated

Exclusive A critical, currently unpatched bug in Chromium's Blink rendering engine can be abused to crash many Chromium-based browsers within seconds, causing a denial-of-service condition – and, in some tests, freezing the host system. Security researcher Jose Pino found the flaw, and created a proof-of-concept exploit, Brash, to demonstrate the vulnerability affecting billions of people worldwide. Chrome is the most popular browser in the world with over 70% market share, according to StatCounter, and that's not counting all the people who use any of the open source Chromium-based browsers, including Microsoft Edge, OpenAI's ChatGPT Atlas, Brave, and Vivaldi. Given the ITU counts 5.5 billion internet users, that suggests Chrome alone is used by more than 3 billion people. Brash exploits an architectural flaw in Blink, the rendering engine used by Chromium-based browsers. After testing the PoC on 11 major browsers on Android, macOS, Windows, and Linux, Pino found it works on nine of them, causing those browsers to collapse in 15 to 60 seconds. It affects Chromium versions 143.0.7483.0 and later. "The attack vector originates from the complete absence of rate limiting on document.title API updates," Pino said in research published on GitHub. "This allows injecting millions of DOM mutations per second, and during this injection attempt, it saturates the main thread, disrupting the event loop and causing the interface to collapse." The Register tested the code on Edge, and not ...

Read full article

Affected Software

5 affected components
Google Chrome
OpenAI ChatGPT Atlas
Microsoft Edge
Brave Software Brave
Vivaldi Technologies Vivaldi
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical, unpatched vulnerability in the Chromium's Blink rendering engine that can cause denial-of-service issues.

2

What security implications are discussed?

The vulnerability could lead to crashing multiple Chromium-based browsers and potentially freezing the host operating system.

3

What products or software are affected?

The affected software includes Google Chrome, Microsoft Edge, Brave Browser, Vivaldi, and other Chromium-based browsers.

4

Is there a fix available for this vulnerability?

No, there is currently no fix available for this critical bug in Chromium.

5

What actions should users take to protect themselves?

Users should be cautious while browsing and consider limiting their use of affected browsers until a patch is released.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203