Brash Exploit Crashes Chromium-Based Browsers via Document Title API
Summary
Hide ▲
Show ▼
A vulnerability in Chromium's Blink rendering engine, dubbed Brash, can crash Chromium-based browsers within 15-60 seconds by exploiting the document.title API. The flaw allows for rapid DOM mutations, leading to browser crashes and system performance degradation. The attack can be timed to execute at specific moments, functioning like a logic bomb. Affected browsers include Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi, Arc Browser, Dia Browser, OpenAI ChatGPT Atlas, and Perplexity Comet. Mozilla Firefox and Apple Safari are not affected. The exploit involves three phases: hash generation, burst injection, and UI thread saturation. The attack can be triggered by a single malicious URL, causing the browser to become unresponsive and require forced termination.
Timeline
-
30.10.2025 16:45 1 articles · 11d ago
Brash Exploit Disclosed in Chromium-Based Browsers
A vulnerability in Chromium's Blink rendering engine, dubbed Brash, can crash Chromium-based browsers within 15-60 seconds by exploiting the document.title API. The flaw allows for rapid DOM mutations, leading to browser crashes and system performance degradation. The attack can be timed to execute at specific moments, functioning like a logic bomb. Affected browsers include Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi, Arc Browser, Dia Browser, OpenAI ChatGPT Atlas, and Perplexity Comet. Mozilla Firefox and Apple Safari are not affected.
Show sources
- New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL — thehackernews.com — 30.10.2025 16:45
Information Snippets
-
Brash exploits a lack of rate limiting on document.title API updates.
First reported: 30.10.2025 16:451 source, 1 articleShow sources
- New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL — thehackernews.com — 30.10.2025 16:45
-
The attack can inject approximately 24 million updates per second.
First reported: 30.10.2025 16:451 source, 1 articleShow sources
- New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL — thehackernews.com — 30.10.2025 16:45
-
The exploit can be timed to execute at specific moments.
First reported: 30.10.2025 16:451 source, 1 articleShow sources
- New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL — thehackernews.com — 30.10.2025 16:45
-
Affected browsers include Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi, Arc Browser, Dia Browser, OpenAI ChatGPT Atlas, and Perplexity Comet.
First reported: 30.10.2025 16:451 source, 1 articleShow sources
- New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL — thehackernews.com — 30.10.2025 16:45
-
Mozilla Firefox and Apple Safari are not affected by Brash.
First reported: 30.10.2025 16:451 source, 1 articleShow sources
- New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL — thehackernews.com — 30.10.2025 16:45
-
The attack can be triggered by a single malicious URL.
First reported: 30.10.2025 16:451 source, 1 articleShow sources
- New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL — thehackernews.com — 30.10.2025 16:45