AfterDawn: Tech news

Security firm exploits serious Google Chrome browser bug

Written by James Delahunty @ 10 May 2011 11:11 User comments (4)

Security firm exploits serious Google Chrome browser bug VUPEN Security has announced the discovery of a vulnerability in Google's Chrome browser software.
Google Chrome has survived assaults at the Pwn2Own contest for the last three years. Now, French security firm VUPEN says it is unhappy to announced that it has officially "Pwned" Google Chrome and its protective Sandbox measures.

VUPEN uploaded a video of the browser exploit in action which bypasses all security features including ASLR/DEP/Sandbox, without exploiting a Windows kernel vulnerability. It works on all Windows systems and with the latest versions of the Chrome browser.

In the video, a web page is loaded displaying just a text message - "Your browser is being Pwned!" - and after a few seconds of inactivity (and without a visible crash in Chrome), the windows calculator application runs. According to the VUPEN write-up, the calculator executable is downloaded and executed.

At Pwn2Own in March this year, VUPEN successfully attacked Safari in much the same way. A specially crafted web page was loaded and several seconds later, the Mac OS X calculator application was launched and a file was written to the hard drive to demonstrate that the Sandbox had been compromised.



For obvious reasons, the write-up does not disclose technical information on the exploit, only to say that it is one of the most sophisticated codes they have used so far.


Previous Next  

4 user comments

111.5.2011 05:22

Quote:

Now, French security firm VUPEN says it is unhappy to announced that it has officially "Pwned" Google Chrome and its protective Sandbox measures.

LoL...I highly doubt that they are "Unhappy" to have success...next we will have Olympic athletes who are "Unhappy" to win gold!

211.5.2011 08:47

Originally posted by KillerBug:
Quote:

Now, French security firm VUPEN says it is unhappy to announced that it has officially "Pwned" Google Chrome and its protective Sandbox measures.

LoL...I highly doubt that they are "Unhappy" to have success...next we will have Olympic athletes who are "Unhappy" to win gold!
http://www.vupen.com/demos/VUPEN_Pwning_Chrome.php

"We are (un)happy to announce that we have officially Pwned Google Chrome and its sandbox." Of course, they were also happy, but it is something that kinda sucks, considering how Chrome has survived serious attacks like this for so long while its competitors haven't.

311.5.2011 08:48

They shouldn't be unhappy. A good group found an exploit that will be fixed hopefully before it is used for harm. :)

415.5.2011 16:29

Originally posted by KillerBug:
Quote:

Now, French security firm VUPEN says it is unhappy to announced that it has officially "Pwned" Google Chrome and its protective Sandbox measures.

LoL...I highly doubt that they are "Unhappy" to have success...next we will have Olympic athletes who are "Unhappy" to win gold!
Gotta agree here.
While they may be unhappy for Google & it's success at being unbeatable till now, I'm positive that they're very proud about their coding prowess.
Yes, they are happy me thinx.

Also, I'm Very Glad they haven't released the exploit code before the vendor can make a patch, like some titwads do. Clear violation of the rules those of us who have fought this malware stuff lived by.

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive