Google has published exploit code for a security problem in Chromium, the engine used by browsers like Google Chrome, Microsoft Edge, Brave, and Opera.
The problem is linked to the Fetch API feature, which helps websites handle background internet requests.
Security researchers say hackers could misuse it to keep hidden connections active in a userโs browser, allowing attackers to send large amounts of traffic to websites or build browser-based botnets.
What makes the situation especially concerning is that some browser sessions may continue maintaining these connections even after the browser or device has been restarted.
Reports also indicate the vulnerability had been known internally for more than two years before proof-of-concept exploit code became public.