Google accidentally exposed details of unfixed Chromium flaw
2026-05-22T01:23:30Z•3cfa491f8eac7e1c4d13ab2b5f3efdb3aa861250db16a8f5e98b5157f76d41b7
arch linuxbrowser vulnerabilitychromiumcisco secure workloadcritical updatedrupalfirst vpn seizure','vpn service seizure'','apple app store fraudgithub breachgooglegrafanajfmbackdoormfa bypassmicrosoft defendernpmpinTheftprivilege escalationremote code executionshowboatsite admin privilegessonicwallsupply chaintanstacktelco malwaretoken rotationzero-day
What happened
Collection of BleepingComputer headlines (May 20–21, 2026) covering multiple high-impact security events: an accidental Chromium disclosure of an unfixed browser flaw that can keep JavaScript running after browser close and enable remote code execution; Microsoft rolling patches for two Defender zero-days exploited in the wild; a maximum-severity Cisco Secure Workload vulnerability that can grant Site Admin privileges; SonicWall Gen6 SSL‑VPN MFA bypasses tied to incomplete patching; supply‑chain incidents (TanStack npm compromise) leading to GitHub and Grafana breaches due to missed token/work
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 3cfa491f8eac7e1c4d13ab2b5f3efdb3aa861250db16a8f5e98b5157f76d41b7
- Enrichment time
- 2026-05-22T01:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.