Google Chrome, Microsoft Edge zero-day vulnerability shared on Twitter

Discussion in 'other security issues & news' started by Minimalist, Apr 13, 2021.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    https://www.bleepingcomputer.com/ne...dge-zero-day-vulnerability-shared-on-twitter/
     
  2. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,972
    Location:
    USA
    Hmmm ... says the zero-day cannot currently escape Chrome's sandbox, so it has to work with another vulnerability to turn it off.
     
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    Yes luckily sandbox prevents escape. Google will also probably quickly release update.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I read it's the same bug that was used in Pwn2Own 2021, but I assume they did manage to escape the sandbox. But apparently they used a second hole in either Chrome or Windows to bypass Chrome's sandbox.
     
  5. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,102
    Location:
    Canada
    I would really like to see a clear explanation on this: they escaped the sandbox with the 2021 Pwn2Own exploit or they didn't.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I don't think they will pay so much for remote code execution without a sandbox escape. I assume when calc.exe is being launched after exploitation, it's runnning with at least medium rights.
     
  7. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,102
    Location:
    Canada
    That does make sense, although I wish they would provide more information.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Apparently, certain companies were once again being hacked via a Chrome exploit combined with a Windows kernel exploit in order to escape Chrome's sandbox. These type of exploits are almost never being used against home user PC's, but still a good reminder that browsers can still be hacked. So especially companies can use a little bit of extra protection, that's why they often use EDR systems. So if AV's fail to detect malware, behavior monitoring tools should still alert about suspicious behavior.

    https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/
     
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.