Select Menu

Slider

Windows

Apple | Mac

Linux

Mobile

Hardware

Tutorial

Android

» » » » » Google fixes Chrome vulnerabilities exploited at Pwn2Own contest
«
Next
Newer Post
»
Previous
Older Post

Google released emergency security updates for Chrome in order to patch critical vulnerabilities demonstrated Thursday by a security researcher at the Mobile Pwn2Own hacking competition.
The vulnerabilities were exploited by a security researcher who uses the pseudonym Pinkie Pie to achieve arbitrary code execution on a Nexus 4 and a Samsung Galaxy S4 device, earning him a prize of US$50,000 in the contest.
Following Pinkie Pie's demonstration, the vulnerabilities were reported to Google, which took less than a day to fix them and push out new patches.
Even though the researcher demonstrated his exploit on Chrome for Android, Google also fixed the vulnerabilities in Chrome for Windows, Mac and Linux, as well as in Chrome Frame plug-in for Internet Explorer.
Google describes the vulnerabilities only as "multiple memory corruption issues," but the Pwn2Own contest organizers said Pinkie Pie's attack exploited an integer overflow and a separate vulnerability that allowed for a full sandbox escape.
Google Chrome's application sandbox separates the browser's processes from the operating system, making it difficult to achieve arbitrary code execution. Pinkie Pie demonstrated Chrome sandbox escape exploits before in 2012, as part of Google's own Pwnium contests.
Source : PCWorld

About Unknown

This is a short description in the author block about the author. You edit it by entering text in the "Biographical Info" field in the user admin panel.
«
Next
Newer Post
»
Previous
Older Post

No comments

Leave a Reply