<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member]]></title><description><![CDATA[<p>back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member</p><p>in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser</p><p>today, almost 4 years later, the bug is finally public:<br /><a href="https://issues.chromium.org/issues/40062121" rel="nofollow noopener"><span>https://</span><span>issues.chromium.org/issues/400</span><span>62121</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/14b72ea9-dba5-4cae-867c-181fc7661bf5/back-in-2022-i-found-a-bug-that-would-let-me-with-no-user-interaction-turn-any-chromium-based-browser-into-a-permanent-js-botnet-member</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 05:43:42 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/14b72ea9-dba5-4cae-867c-181fc7661bf5.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 20 May 2026 11:42:20 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 16:33:02 GMT]]></title><description><![CDATA[<p><span><a href="https://toot.aquilenet.fr/@Strabisme">@<span>Strabisme</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> yes, provided you disable js or service workers on the page</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607862876920908</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607862876920908</guid><dc:creator><![CDATA[rebane2001@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 16:33:02 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 16:27:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> really cool work. Didn't realize this sort of bug class even existed. Hope they up the bounty; this seems worth more than $1000</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/shravanrn/statuses/116607839258118513</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/shravanrn/statuses/116607839258118513</guid><dc:creator><![CDATA[shravanrn@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 16:27:02 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 16:14:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> I hate it; but damn that's clever.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116607788773559053</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116607788773559053</guid><dc:creator><![CDATA[fuzzyfuzzyfungus@cyberplace.social]]></dc:creator><pubDate>Wed, 20 May 2026 16:14:11 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 16:06:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> <span><a href="/user/samantazfox%40infosec.exchange">@<span>SamantazFox</span></a></span> It's on archive.today/.is/.ph. Only go there with a content blocker, you're DDoSing a small blog otherwise: <a href="https://gyrovague.com/2026/02/01/archive-today-is-directing-a-ddos-attack-against-my-blog/" rel="nofollow noopener"><span>https://</span><span>gyrovague.com/2026/02/01/archi</span><span>ve-today-is-directing-a-ddos-attack-against-my-blog/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/Lenni/statuses/116607756616035726</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/Lenni/statuses/116607756616035726</guid><dc:creator><![CDATA[lenni@fosstodon.org]]></dc:creator><pubDate>Wed, 20 May 2026 16:06:01 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 16:04:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/samantazfox%40infosec.exchange">@<span>SamantazFox</span></a></span> out of curiosity, where? the archive.org captures don't load for me</p><p>edit: ty <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607751274057081</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607751274057081</guid><dc:creator><![CDATA[rebane2001@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 16:04:39 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 15:43:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> Well, too late, it has already been archived :x</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/SamantazFox/statuses/116607669821811656</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/SamantazFox/statuses/116607669821811656</guid><dc:creator><![CDATA[samantazfox@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 15:43:56 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 15:36:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> fucking embarrassing</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/ratsnakegames/statuses/116607640959039248</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/ratsnakegames/statuses/116607640959039248</guid><dc:creator><![CDATA[ratsnakegames@mastodon.social]]></dc:creator><pubDate>Wed, 20 May 2026 15:36:36 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 15:34:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> Nice find! I should have woken up earlier to see the details. <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title="😅" alt="😅" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116607632791636916</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/AlesandroOrtiz/statuses/116607632791636916</guid><dc:creator><![CDATA[alesandroortiz@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 15:34:31 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 15:22:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> Oops.</p>]]></description><link>https://board.circlewithadot.net/post/https://eldritch.cafe/users/Sylvhem/statuses/116607584789479923</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://eldritch.cafe/users/Sylvhem/statuses/116607584789479923</guid><dc:creator><![CDATA[sylvhem@eldritch.cafe]]></dc:creator><pubDate>Wed, 20 May 2026 15:22:19 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 15:21:23 GMT]]></title><description><![CDATA[<p>issue set to private again, hopefully it'll get fixed properly this time <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61b.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--stuck_out_tongue" style="height:23px;width:auto;vertical-align:middle" title=":p" alt="😛" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607581137310739</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607581137310739</guid><dc:creator><![CDATA[rebane2001@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 15:21:23 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 15:12:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> BeEF module ftw! <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f389.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--tada" style="height:23px;width:auto;vertical-align:middle" title="🎉" alt="🎉" /></p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/skyr/statuses/116607545981882399</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/skyr/statuses/116607545981882399</guid><dc:creator><![CDATA[skyr@chaos.social]]></dc:creator><pubDate>Wed, 20 May 2026 15:12:27 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 15:08:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> Clearly, <span><a href="https://mastodon.social/@mozilla">@<span>mozilla</span></a></span>'s choices around not implementing certain APIs is paying off.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/egerlach/statuses/116607532399026170</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/egerlach/statuses/116607532399026170</guid><dc:creator><![CDATA[egerlach@hachyderm.io]]></dc:creator><pubDate>Wed, 20 May 2026 15:08:59 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 14:38:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange" rel="nofollow noreferrer noopener">@<span>rebane2001</span></a></span> peak google efficiency</p>]]></description><link>https://board.circlewithadot.net/post/https://has.siktir.in/users/gurkan/statuses/01KS2X64XQQKJ1RBFK0FERRPXF</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://has.siktir.in/users/gurkan/statuses/01KS2X64XQQKJ1RBFK0FERRPXF</guid><dc:creator><![CDATA[gurkan@has.siktir.in]]></dc:creator><pubDate>Wed, 20 May 2026 14:38:41 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 14:38:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/henry_null%40sueden.social">@<span>henry_null</span></a></span> <span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> </p><p>i second this, sent from my epiphany</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/utf_7/statuses/116607412252465261</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/utf_7/statuses/116607412252465261</guid><dc:creator><![CDATA[utf_7@mastodon.social]]></dc:creator><pubDate>Wed, 20 May 2026 14:38:26 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 14:06:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f926.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--face_palm" style="height:23px;width:auto;vertical-align:middle" title="🤦" alt="🤦" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️</p>]]></description><link>https://board.circlewithadot.net/post/https://thx.gg/users/interpipes/statuses/116607285790905574</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://thx.gg/users/interpipes/statuses/116607285790905574</guid><dc:creator><![CDATA[interpipes@thx.gg]]></dc:creator><pubDate>Wed, 20 May 2026 14:06:17 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 14:04:12 GMT]]></title><description><![CDATA[<p><span><a href="/user/edcates%40mastodon.social">@<span>EdCates</span></a></span> <span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> I mean its them who made it public first I guess<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" /> <a href="https://issues.chromium.org/issues/40062121#comment56" rel="nofollow noopener"><span>https://</span><span>issues.chromium.org/issues/400</span><span>62121#comment56</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://sueden.social/users/henry_null/statuses/116607277637364962</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://sueden.social/users/henry_null/statuses/116607277637364962</guid><dc:creator><![CDATA[henry_null@sueden.social]]></dc:creator><pubDate>Wed, 20 May 2026 14:04:12 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 14:02:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> well that's not good...</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/TagHunt/statuses/116607269452129570</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/TagHunt/statuses/116607269452129570</guid><dc:creator><![CDATA[taghunt@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 14:02:07 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 13:59:46 GMT]]></title><description><![CDATA[<span><a href="/user/rebane2001%40infosec.exchange" rel="ugc">@<span>rebane2001</span></a></span> uh oh<br />Why did it take them 4 years to (not) fix this?<br />I really should go ahead and disable js everywhere]]></description><link>https://board.circlewithadot.net/post/https://tsogol.tsiran.org/objects/36fc4464-5db8-4e4a-b920-bf694f11966b</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tsogol.tsiran.org/objects/36fc4464-5db8-4e4a-b920-bf694f11966b</guid><dc:creator><![CDATA[mirq@tsogol.tsiran.org]]></dc:creator><pubDate>Wed, 20 May 2026 13:59:46 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 13:53:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> no</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607235566792620</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/rebane2001/statuses/116607235566792620</guid><dc:creator><![CDATA[rebane2001@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 13:53:30 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 13:51:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> I've got a dumb question: Is this something that can be mitigated with a uBlock filter? It reads like it could be but I don't know this stuff well.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116607229509757224</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116607229509757224</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 13:51:58 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 13:45:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange" rel="nofollow noopener">@<span>rebane2001</span></a></span> the bot ghost is providing emotional support here</p><blockquote><p>Uh oh! This issue still open and hasn't been updated in the last 262 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?</p></blockquote>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.catgirl.cloud/users/multisn8/statuses/116607205590639122</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.catgirl.cloud/users/multisn8/statuses/116607205590639122</guid><dc:creator><![CDATA[multisn8@mastodon.catgirl.cloud]]></dc:creator><pubDate>Wed, 20 May 2026 13:45:53 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 13:39:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/henry_null%40sueden.social">@<span>henry_null</span></a></span> <span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> Cue Microsoft issuing a press release accusing Rebane of "violating coordinated vulnerability best practices."  They've barely had time to react, after all...</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/EdCates/statuses/116607179571712274</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/EdCates/statuses/116607179571712274</guid><dc:creator><![CDATA[edcates@mastodon.social]]></dc:creator><pubDate>Wed, 20 May 2026 13:39:16 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 13:09:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange">@<span>rebane2001</span></a></span> Is this what they call a 1259 day?</p>]]></description><link>https://board.circlewithadot.net/post/https://sueden.social/users/henry_null/statuses/116607063829235226</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://sueden.social/users/henry_null/statuses/116607063829235226</guid><dc:creator><![CDATA[henry_null@sueden.social]]></dc:creator><pubDate>Wed, 20 May 2026 13:09:50 GMT</pubDate></item><item><title><![CDATA[Reply to back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member on Wed, 20 May 2026 12:47:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/rebane2001%40infosec.exchange" rel="nofollow noopener">@<span>rebane2001</span></a></span> <span><a href="/user/natty%40astolfo.social" rel="nofollow noopener">@<span>natty</span></a></span> they are very similar afaik, mostly branding because Germany has another established thing called "focus"</p><p>But I'll retry in fennec in a sec</p>]]></description><link>https://board.circlewithadot.net/post/https://unfug.social/users/4censord/statuses/116606976782999186</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://unfug.social/users/4censord/statuses/116606976782999186</guid><dc:creator><![CDATA[4censord@unfug.social]]></dc:creator><pubDate>Wed, 20 May 2026 12:47:41 GMT</pubDate></item></channel></rss>