
During that window, threat actors, whose ability to build exploit kits has been “wildly accelerated” by AI, likely had time to reverse engineer exploits from the open source codebase and take advantage of what used to seem like a reasonable patch gap, Ioussoufovitch explained.
“Attackers are acting faster, and that means each day a patch is delayed carries more risk than it used to,” he said.
Effectively, at the Chromium source level, it was an N-day vulnerability (it was known and had an available patch), but in Google Chrome, it was effectively a zero-day (previously unknown) flaw, the Proofpoint threat team pointed out, noting, “a fully weaponized Chrome exploit chain has historically been a high-value, rare capability.”
