{"id":181752,"date":"2026-05-26T14:48:51","date_gmt":"2026-05-26T12:48:51","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium"},"modified":"2026-05-26T14:48:51","modified_gmt":"2026-05-26T12:48:51","slug":"google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","title":{"rendered":"Google ha accidentalmente rivelato i dettagli di una vulnerabilit\u00e0 non corretta in Chromium","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>La societ\u00e0 Google ha accidentalmente aperto l'accesso pubblico a un rapporto (copia pubblica) contenente una spiegazione dettagliata e un esempio di exploit per una vulnerabilit\u00e0 ancora non corretta nel motore Chromium. La vulnerabilit\u00e0 \u00e8 stata considerata pericolosa e al ricercatore che ha identificato il problema \u00e8 stato conferito un premio di $1000. Le informazioni sul problema sono state inviate nel 2022 e da allora sono state sollevate periodicamente, ma la discussione sulla sua correzione (era necessaria l'attuazione di nuovi limiti sul caricamento continuo) non \u00e8 stata portata a termine. In una di queste discussioni, gli sviluppatori hanno erroneamente ritenuto che la vulnerabilit\u00e0 fosse stata corretta e hanno aperto l'accesso pubblico alle informazioni, anche se il problema rimaneva irrisolto.<\/p>\n<p>La vulnerabilit\u00e0 consente la continuazione dell'esecuzione di un gestore JavaScript in background (Service Worker) anche dopo la chiusura della finestra del browser, il che d\u00e0 all'attaccante l'opportunit\u00e0 di organizzare un controllo costante sul browser con la possibilit\u00e0 di caricare ed eseguire in qualsiasi momento il proprio codice JavaScript nel contesto della propria pagina. Lo scenario d'attacco consiste nel fatto che l'attaccante pu\u00f2 ottenere l'apertura della propria pagina in una versione del browser priva di vulnerabilit\u00e0, dopodich\u00e9 pu\u00f2 attendere l'emergere di una grave vulnerabilit\u00e0 nel browser e organizzare l'esecuzione dell'exploit senza la necessit\u00e0 di un riapertura della pagina da parte dell'utente. Il concetto del metodo consiste nella creazione di una pagina con Service Worker che esegue un'operazione di caricamento dati che non viene mai interrotta. <\/p>\n<p>Secondo il ricercatore che ha identificato il problema, la vulnerabilit\u00e0 pu\u00f2 essere utilizzata per creare un botnet di browser, gli utenti dei quali non sospettano che una volta ancorato, l'attaccante possa eseguire JavaScript in remoto sui loro dispositivi senza alcuna azione da parte loro. Tale botnet, anche senza sfruttare altre vulnerabilit\u00e0, pu\u00f2 essere utilizzata per organizzare attacchi DDoS e per il proxying di traffico dannoso attraverso i sistemi delle vittime. Il problema riguarda tutti i browser basati sul motore Chromium.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65491\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u0440\u0438\u0437\u043d\u0430\u043d\u0430 \u043e\u043f\u0430\u0441\u043d\u043e\u0439 \u0438 \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0435\u043c\u0443 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0431\u044b\u043b\u043e \u0432\u044b\u043f\u043b\u0430\u0447\u0435\u043d\u043e \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0435 \u0432 $1000. \u0418\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u0431\u044b\u043b\u0430 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0430 \u0435\u0449\u0451 \u0432 2022 \u0433\u043e\u0434\u0443 \u0438 \u0441 \u0442\u0435\u0445 \u043f\u043e\u0440 \u043f\u0435\u0440\u0438\u043e\u0434\u0438\u0447\u0435\u0441\u043a\u0438 \u043f\u043e\u0434\u043d\u0438\u043c\u0430\u043b\u043e\u0441\u044c, \u043d\u043e \u043d\u0435 \u0434\u043e\u0432\u043e\u0434\u0438\u043b\u043e\u0441\u044c \u0434\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181752","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0434\u0435\u0442\u0430\u043b\u0438 \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Chromium | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-26T12:48:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-26T12:48:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Google ha accidentalmente rivelato i dettagli di una vulnerabilit\u00e0 non corretta in Chromium | ProHoster","description":"La societ\u00e0 Google ha accidentalmente aperto l'accesso pubblico a un rapporto (copia pubblica) contenente una spiegazione dettagliata e un esempio di exploit per una vulnerabilit\u00e0 ancora non corretta nel motore Chromium.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u0440\u0430\u0441\u043a\u0440\u044b\u043b \u0434\u0435\u0442\u0430\u043b\u0438 \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 Chromium | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u0441\u043b\u0443\u0447\u0430\u0439\u043d\u043e \u043e\u0442\u043a\u0440\u044b\u043b\u0430 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0442\u0447\u0451\u0442\u0443 (\u043e\u0431\u0449\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u0430\u044f \u043a\u043e\u043f\u0438\u044f), \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u043c\u0443 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u0438 \u043f\u0440\u0438\u043c\u0435\u0440 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u0430 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0435\u0449\u0451 \u043d\u0435 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u0432 \u0434\u0432\u0438\u0436\u043a\u0435 Chromium.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/google-sluchajno-raskryl-detali-neispravlennoj-uyazvimosti-v-chromium","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-26T12:48:51+00:00","article:modified_time":"2026-05-26T12:48:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/181752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=181752"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/181752\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=181752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=181752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=181752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}