Security Experts Stunned as Google Chrome Hacked
A French security firm says it now knows how to hack its way into Google's Chrome browser. If the claim turns out to be true, it would represent a surprising weakness for a web browser considered by some to be the safest available.
The hack report comes from France's Vupen, which says it was able to sidestep Chrome's defenses -- including the highly reputable sandbox design -- as well as Windows 7's built-in anti-exploit infrastructure.
Report Stuns Security Experts
The exploit is "one of the most sophisticated codes we have seen and created so far, as it bypasses all security features including ASLR / DEP / Sandbox," Vupen reported.
"It is silent (no crash after executing the payload), it relies on undisclosed (zero-day) vulnerabilities and it works on all Windows systems."
The report is a surprise to many since Chrome is considered a very difficult browser to hack.
Sandbox Buffers Between Browser and Operating System
Chrome's sandbox infrastructure is engineered to create a buffer between the browser and the wider operating system (OS), making it much more difficult for a hacker to take advantage of a PC. In theory, sandboxing creates a virtual wall such that a running program has limited access to the 'outside' operating system.
So resilient is Google's web browser sandbox design that white-hat hackers were unable to exploit it at a recent Pwn2Own competition.
Nevertheless, Vupen has not only described how it exploited Chrome on its blog, but it's also posted a video of the process on YouTube. (Source: theregister.co.uk)
Vupen Not Communicating With Google
Google says Vupen never contacted it about the security hole. Therefore, the search giant has been unable to confirm its report. "We're unable to verify Vupen's claims at this time as we have not received any details from them," Google said in a recent statement.
"Should any modifications become necessary, users will be automatically updated to the latest version of Chrome." (Source: computerworld.com)
Had it pursued a different tactic by reporting the issue directly to Google, Vupen may have been privy to a large reward. So far this year Google has already handed out $77,000 in "bug bounties" to various security experts.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.