Google accidentally exposed details of unfixed Chromium flaw

2026-05-22T01:23:30Z3cfa491f8eac7e1c4d13ab2b5f3efdb3aa861250db16a8f5e98b5157f76d41b7
arch linuxbrowser vulnerabilitychromiumcisco secure workloadcritical updatedrupalfirst vpn seizure','vpn service seizure'','apple app store fraudgithub breachgooglegrafanajfmbackdoormfa bypassmicrosoft defendernpmpinTheftprivilege escalationremote code executionshowboatsite admin privilegessonicwallsupply chaintanstacktelco malwaretoken rotationzero-day

What happened

Collection of BleepingComputer headlines (May 20–21, 2026) covering multiple high-impact security events: an accidental Chromium disclosure of an unfixed browser flaw that can keep JavaScript running after browser close and enable remote code execution; Microsoft rolling patches for two Defender zero-days exploited in the wild; a maximum-severity Cisco Secure Workload vulnerability that can grant Site Admin privileges; SonicWall Gen6 SSL‑VPN MFA bypasses tied to incomplete patching; supply‑chain incidents (TanStack npm compromise) leading to GitHub and Grafana breaches due to missed token/work

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3cfa491f8eac7e1c4d13ab2b5f3efdb3aa861250db16a8f5e98b5157f76d41b7
Enrichment time
2026-05-22T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.