Follow Us

War on Error

Researchers dig deep hole in Chrome's sandbox



It had to happen eventually, but finally someone has found a way to break through Google’s much-vaunted Chrome sandbox security, which let’s remind ourselves, first appeared in the browser as long ago as 2008.

As exploits go, the one publicised by security researchers VUPEN is about as good as it gets and appears to 'pwn' Chrome (that is, v10.696.65 running on 64-bit Windows 7 SP1) completely.

It works on all versions of Windows, it exploits a previously unknown 0-day flaw that is not related to kernel mode, and it doesn’t crash the browser. This isn’t just the sandbox but the ASLR (Address Space Layout Randomisation) and DEP (Data Execution Prevention) that goes with it, so it’s the crown jewels.

The demo video shows the researchers running a calculator app within the browser as a way of proving that it has been broken. The company has no plans to explain the exploit but presumably Google will be fed the details to allow a fix.

Chrome users are now in limbo, unsure of how the sandbox was broken, and without a fix. Google has yet to comment. Exactly what happens next will depend on whether the issue undermines the sandbox in a way that requires a major redesign or just causes a problem that can be patched in the short term. Clearly, the sandbox as users have known it is probably dead and gone.

I’d suggest they are still better off than having no sandboxing at all - Chrome has a generally good reputation in terms of security. It was also the only browser to survive the Pwn2Own contest intact in a contest that saw the other major browsers fall.

Time to shrug and wait for Sandbox II.


Email this to a friend

* indicates mandatory field





Techworld White Papers

Optimising data protection for virtual environments

VM environments require the same level of data protection as does the physical server environment. Companies may use data protection tools built for the physical environment in the virtual world, but this has serious disadvantages.

Download Whitepaper

PCI Compliance: Are UK businesses ready?

Exploring the results of a recent survey, including: ? Levels of understanding of the standard ? Current perceptions of actual compliance status ? Attitudes toward addressing compliance

Download Whitepaper

Mobility Management for Dummies

Your complete guide to managing and securing mobile devices such as laptops and smartphones.

Download Whitepaper

Magic Quadrant for midrange and high-end NAS solutions

It is difficult to find one midrange or high-end NAS product that can cater to all needs. File systems embedded in NAS are often designed to solve one major pain point, with additional features being added later to broaden use cases and benefits.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Complete our survey and you could win a Sony E-book Reader.
Techworld have teamed up with HP to compile a survey relating to server virtualisation. Complete the short survey and you could be the lucky winner of a Sony E-book reader.

Complete the survey here

Site Map

Test