Security News > 2021 > April > RCE Exploit Released for Unpatched Chrome, Opera, and Brave Browsers

An Indian security researcher has publicly published a proof-of-concept exploit code for a newly discovered flaw impacting Google Chrome and other Chromium-based browsers like Microsoft Edge, Opera, and Brave.
Released by Rajvardhan Agarwal, the working exploit concerns a remote code execution vulnerability in the V8 JavaScript rendering engine that powers the web browsers.
According to the screenshot shared by Agarwal, the PoC HTML file, and its associated JavaScript file, can be loaded in a Chromium-based browser to exploit the security flaw and launch the Windows calculator app.
It's worth noting that the exploit needs to be chained with another flaw that can allow it to escape Chrome's sandbox protections.
While Google has addressed the issue in the latest version of V8, it's yet to make its way to the stable channel, thereby leaving the browsers vulnerable to attacks.
Google is expected to ship Chrome 90 later today, but it's not clear if the release will include a patch for the V8 flaw.
News URL
http://feedproxy.google.com/~r/TheHackersNews/~3/xnTh85fU5Rk/rce-exploit-released-for-unpatched.html
Related news
- Critical Erlang/OTP SSH pre-auth RCE is 'Surprisingly Easy' to exploit, patch now (source)
- Critical Erlang/OTP SSH RCE bug now has public exploits, patch now (source)
- Craft CMS RCE exploit chain used in zero-day attacks to steal data (source)
- PoC exploit for SysAid pre-auth RCE released, upgrade quickly! (source)
- Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell (source)
- Google Chrome to block admin-level browser launches for better security (source)
- Google fixes high severity Chrome flaw with public exploit (source)
- New EDDIESTEALER Malware Bypasses Chrome's App-Bound Encryption to Steal Browser Data (source)
- ⚡ Weekly Recap: APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More (source)
- Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild (source)