Google rushes out Chrome patch for Pwnium zero-day flaws
Summary: According to a Google advisory, the zero-day flaws related to universal cross-site scripting (UXSS) and bad history navigation.
VANCOUVER -- The Google Chrome security team wasted no time fixing the gaping security holes exploited by a Russian university student as part of this year's inaugural Pwnium hacker challenge.
Less than 24 hours after Sergey Glazunov hacked into a fully patched Windows 7 machine with a pair of Chrome zero-day flaws, Google rushed out a patch for Windows, Mac OS X, Linux and Chrome Frame users.
Technical details of the vulnerabilities are being kept under wraps until the patch is pushed out via the browser's silent/automatic update mechanism.
According to Google's advisory, the flaws related to universal cross-site scripting (UXSS) and bad history navigation.
- [Ch-ch-ch-ch-ching!!! $60,000] [117226] [117230] Critical CVE-2011-3046: UXSS and bad history navigation. Credit to Sergey Glazunov.
Glazunov's exploit also bypassed the Chrome sandbox to execute code with full permissions of the logged on user.
The Google browser was also popped by a hacking team from VUPEN and there's speculation that a vulnerability in the Flash Player plugin was exploited in that attack. VUPEN co-founder Chaouki Bekrar told me that the flaw existed in the default installation of Chrome but he declined to say if the faulty code was created by Google or a third-party vendor.
The Flash Player plugin in Chrome runs in a weaker sandbox than the full browser and has always been a tempting target for attackers.
Google is working on putting Flash within the more robust plugin and I'd told this will happen before the end of this year.
ALSO SEE:
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
Kudos Google...
Why have they not patched earlier explots in Chrome then?
:|
Why?
Almost as easy...
I wonder???
4
Google rushes out Chrome patch for Pwnium zero-day flaws
That's fast!
One wonders how many unreported IE, Firefox, Safari and Opera vulnerabilities VUPEN (and similar outfits) has created exploits for. Not to mention Flash Player and Java. And does VUPEN also discover/buy vulnerabilities to create exploits for Mac OS X and desktop Linux?
You mean...
You mean did some of their pals get busted in that Russian raid last year? Good question.
How do you know that for sure?
most importnat thing is missing
I still love you, Chrome...
It's the game we play by having modern toys, and no one is truly immune (Regardless of marketing "geniuses" or "fanboys" telling you that).
Well..
Since you're talking about yourself, we'll keep that in mind.
Well...