Google Chrome has amassed quite a favorable reputation for security with both users and security researchers. To its credit, it is the only web browser to have never been hacked at the annual Pwn2Own hacking competition. In fact, on the first day of this year’s Pwn2Own contest (Mar 9-11), Google even offered a $20,000 cash prize to anybody who could circumnavigate the browser’s sandbox “using vulnerabilities purely present in Google-written code.” While no one managed to claim the prize back then, researchers from French security firm VUPEN now claim to have finally “Pwnd Google Chrome and its sandbox.” Hit the jump for more.
The company announced its success in a blog post on Monday. In keeping with the company's stated policy, the technical details of the vulnerability are only available to its government customers. Nonetheless, the company did share a short video (below) showing the exploit in action.
“The exploit shown in this video is one of the most sophisticated codes we have seen and created so far as it bypasses all security features including ASLR/DEP/Sandbox,” the company said, “it is silent (no crash after executing the payload), it relies on undisclosed (0day) vulnerabilities discovered by VUPEN and it works on all Windows systems (32-bit and x64).
“The video shows the exploit in action with Google Chrome v11.0.696.65 on Microsoft Windows 7 SP1 (x64). The user is tricked into visiting a specially crafted web page hosting the exploit which will execute various payloads to ultimately download the Calculator from a remote location and launch it outside the sandbox at Medium integrity level.”
A Google spokesperson simply said that the company was not in a position to verify VUPEN's claims "as we have not received any details from them."
I do really like the pwn2own deal though, you really have some of the most talented people actually doing some good.....instead of bitching about a company for sueing somebody and then hacking them and stealing credit card information....
Oh if only talking smack about google was as "hip" and "cool" as talking about Microsoft or Sony....
I highly doubt the credit card info was stolen because of the lawsuit with geohot. They gained access and a hacker said hey lets snoop around and then they found all the CC and personal info right ou in the open on the dev network.
Log in to MaximumPC directly or log in using Facebook
maximumpc: Gigabyte's G1 Sniper for Z87 is sitting here looking sexy: http://t.co/mcpnueKhQK4 hours 17 min ago
maximumpc: Apple claims the Samsung S4 violates several patents relating to Siri, voice search and more: http://t.co/jOjCWtynVk via @DailyTech5 hours 38 min ago
maximumpc: ASRock releases video of its upcoming 8 series waterproof mobos for the ultra overclockers: http://t.co/4gwxgZjkfg7 hours 35 min ago