Windows 7 Forums


Windows 7: Security Group Claims to Have Subverted Google Chrome’s Sandbox

09 May 2011   #1

Windows 7 Home Premium 64bit
Los Angeles
 
 
Security Group Claims to Have Subverted Google Chrome’s Sandbox

Quote:
A French security research firm boasted today that it has discovered a two-step process for defeating Google Chrome‘s sandbox, the security technology designed to protect the browser from being compromised by previously unknown security flaws. Experts say the discovery, if true, marks the first time hackers have figured out a way around the vaunted security layer, and almost certainly will encourage attackers to devise similar methods of subverting this technology in Chrome and other widely used software.
In an advisory released today, VUPEN Security said “We are (un)happy to announce that we have official Pwnd Google Chrome and its sandbox.” The post includes a video showing the exploitation of what VUPEN claims is a previously undocumented security hole in Chrome v.11.0.696.65 on Microsoft Windows 7 SP1 (x64).



“While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own contest during the last three years, we have now uncovered a reliable way to execute arbitrary code on any installation of Chrome despite its sandbox, ASLR and DEP,” the advisory notes. ASLR and DEP are two of the key security defenses built into Windows Vista and Windows 7
cont here
My System SpecsSystem Spec

10 May 2011   #2

Windows 7 Ultimate x64
 
 
Google sandbox broken

Saw this story today on The Register,

Quote:
Researchers say they've developed attack code that pierces key defenses built into Google's Chrome browser, allowing them to reliably execute malware on end user machines
Whitehats break out of Google Chrome sandbox • The Register
My System SpecsSystem Spec
10 May 2011   #3

Windows 7 x64 / Same
In Your Basement.
 
 

I'm curious as to whether they get double the bounty money.
My System SpecsSystem Spec
.


10 May 2011   #4

Windows 7
 
 

with this news Google should be quick to release a security patch...right?
My System SpecsSystem Spec
10 May 2011   #5

Windows 7 Ult x64 - SP1/ Windows 8 Pro x64
Wanderer
 
 

A patch or new version.

It was only a matter of time...
My System SpecsSystem Spec
Reply

 Security Group Claims to Have Subverted Google Chrome’s Sandbox problems?



Thread Tools



Similar help and support threads for: Security Group Claims to Have Subverted Google Chrome’s Sandbox
Thread Forum
Security Firm Claims Google Is Conspiring To Kill Off Firefox News
Google offering $20,000 for Chrome sandbox exploit Security News
Google Chrome Will Soon Sandbox Flash For More Security Security News
google chrome security alert Browsers & Mail
Google Chrome 5.0.375.99 Stable Includes Security Fixes Browsers & Mail


All times are GMT -5. The time now is 04:59 AM.


Seven Forums Android App Seven Forums IOS App Follow us on Facebook

Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32