{"id":181752,"date":"2026-05-26T14:48:51","date_gmt":"2026-05-26T12:48:51","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium"},"modified":"2026-05-26T14:48:51","modified_gmt":"2026-05-26T12:48:51","slug":"google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","title":{"rendered":"Google revel\u00f3 accidentalmente detalles de una vulnerabilidad no corregida en Chromium","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>La empresa Google abri\u00f3 accidentalmente el acceso p\u00fablico a un informe (copia p\u00fablica) que contiene una explicaci\u00f3n detallada y un ejemplo de exploit para una vulnerabilidad a\u00fan no corregida en el motor Chromium. La vulnerabilidad ha sido considerada peligrosa y se otorg\u00f3 una recompensa de $1000 al investigador que la descubri\u00f3. La informaci\u00f3n sobre el problema se envi\u00f3 en 2022 y desde entonces se ha discutido peri\u00f3dicamente, pero no se ha llevado a cabo la soluci\u00f3n (se requer\u00edan nuevos l\u00edmites para la carga continua). En una de estas discusiones, los desarrolladores asumieron err\u00f3neamente que la vulnerabilidad hab\u00eda sido corregida y abrieron el acceso p\u00fablico a la informaci\u00f3n, a pesar de que el problema segu\u00eda sin resolverse.<\/p>\n<p>La vulnerabilidad permite que un script de JavaScript en segundo plano (Service Worker) contin\u00fae ejecut\u00e1ndose incluso despu\u00e9s de cerrar la ventana del navegador, lo que da a un atacante la posibilidad de mantener un control constante sobre el navegador, pudiendo cargar y ejecutar su propio c\u00f3digo JavaScript en cualquier momento en el contexto de su p\u00e1gina. El escenario de ataque implica que el atacante puede lograr abrir su p\u00e1gina en una versi\u00f3n del navegador que no contenga las vulnerabilidades, y luego esperar a que se descubra una vulnerabilidad significativa en el navegador para organizar la ejecuci\u00f3n del exploit sin necesidad de que el usuario vuelva a abrir la p\u00e1gina del atacante. La esencia del m\u00e9todo radica en crear una p\u00e1gina con un Service Worker que realiza una operaci\u00f3n de carga de datos que nunca se interrumpe. <\/p>\n<p>Seg\u00fan el investigador que identific\u00f3 el problema, la vulnerabilidad puede ser utilizada para crear un botnet a partir de navegadores cuyos usuarios no sospechan que, una vez establecido, el atacante puede ejecutar c\u00f3digo JavaScript de forma remota en sus dispositivos sin que ellos realicen ninguna acci\u00f3n. Dicho botnet, incluso sin explotar otras vulnerabilidades, podr\u00eda ser utilizado para llevar a cabo ataques DDoS y para enrutar tr\u00e1fico malicioso a trav\u00e9s de las v\u00edctimas. El problema afecta a todos los navegadores basados en Chromium.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65491\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u0438\u0437\u043d\u0430\u043d\u0430 \u043e\u043f\u0430\u0441\u043d\u043e\u0439 \u0438 \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0435\u043c\u0443 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0431\u044b\u043b\u043e \u0432\u044b\u043f\u043b\u0430\u0447\u0435\u043d\u043e \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0435 \u0432 $1000. \u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u0431\u044b\u043b\u0430 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0430 \u0435\u0449\u0451 \u0432 2022 \u0433\u043e\u0434\u0443 \u0438 \u0441 \u0442\u0435\u0445 \u043f\u043e\u0440 \u043f\u0435\u0440\u0438\u043e\u0434\u0438\u0447\u0435\u0441\u043a\u0438 \u043f\u043e\u0434\u043d\u0438\u043c\u0430\u043b\u043e\u0441\u044c, \u043d\u043e \u043d\u0435 \u0434\u043e\u0432\u043e\u0434\u0438\u043b\u043e\u0441\u044c \u0434\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181752","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0434\u0435\u0442\u0430\u043b\u0438 \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Chromium | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-26T12:48:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-26T12:48:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Google revel\u00f3 accidentalmente detalles sobre una vulnerabilidad no corregida en Chromium | ProHoster","description":"La empresa Google abri\u00f3 accidentalmente el acceso p\u00fablico a un informe (copia p\u00fablica) que contiene una explicaci\u00f3n detallada y un ejemplo de exploit para una vulnerabilidad a\u00fan no corregida en el motor Chromium.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0434\u0435\u0442\u0430\u043b\u0438 \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Chromium | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-26T12:48:51+00:00","article:modified_time":"2026-05-26T12:48:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/181752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=181752"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/181752\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=181752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=181752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=181752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}