Live data from Hacker News

Chrome 0-day exploit used in Operation WizardOpium

securelist.com

1–10 of 159 posts

Re: Chrome 0-day exploit used in Operation WizardOpium

#10

CVE no. was created in July. I wonder whether the fix took that long.

The CVE number was reserved in July[1]. That doesn't mean the vulnerability was found in July. The vulnerability was reported to Google October 29[2], so between report to fix roll out was only ~2 days. Although the bug tracker entry is hidden[3], you can deduce the time the entry was created by iterating over bug IDs, which indicates it was filed between 8:56 AM PDT[4] and 9:11 AM PDT[5].

The fix was sent for review Oct 29 4:29 PM PDT and submitted at 5:47 PM[6]. It was cherrypicked Oct 30 at 9:51 AM[7].

>Date Entry Created

> 20190718

> Disclaimer: The entry creation date may reflect when the CVE ID was allocated or reserved, and does not necessarily indicate when this vulnerability was discovered, shared with the affected vendor, publicly disclosed, or updated in CVE.

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-13720

[2] https://chromereleases.googleblog.com/2019/10/stable-channel...

[3] https://bugs.chromium.org/p/chromium/issues/detail?id=101922...

[4] https://bugs.chromium.org/p/chromium/issues/detail?id=101922...

[5] https://bugs.chromium.org/p/chromium/issues/detail?id=101922...

[6] https://chromium-review.googlesource.com/c/chromium/src/+/18...

[7] https://chromium.googlesource.com/chromium/src/+/f1b501721e5...

Post reply on HN