Is there somewhere explaining this bug in terms understandable for someone not dabbling in this? I don't really understand how this works to "escape the sandbox". Normally it's like a website you visit that get access it shouldn't have. But this talk about renderers and native apis make it seem like it's stuff another process on the computer would do?
First you compromise the renderer process via e.g. a bug in the JS engine. But even if you have native code execution in the context of the renderer process, you're still in a sandbox. The bug in the OP is for the second stage - breaking out of the sandbox. The referenced `patch.diff` is basically for simulating a compromised renderer.
The Chrome VRP Panel has decided to award $250k for this report
41–50 of 292 posts
Re: The Chrome VRP Panel has decided to award $250k for this report
#42Sandbox escape with high-quality report in Chrome: $250k [1], yet Mozilla will offer you $20k [2] for that... [1] https://bughunters.google.com/about/rules/chrome-friends/574... [2] https://www.mozilla.org/en-US/security/client-bug-bounty/
Won't complain about that.
Re: The Chrome VRP Panel has decided to award $250k for this report
#43Sandbox escape with high-quality report in Chrome: $250k [1], yet Mozilla will offer you $20k [2] for that... [1] https://bughunters.google.com/about/rules/chrome-friends/574... [2] https://www.mozilla.org/en-US/security/client-bug-bounty/
Tells you who is more serious about security. A quarter of $1M is a fair price for this type of bug. Won't complain about that.
Yup, clearly Mozilla.
$250k is loose change for Google.
Re: The Chrome VRP Panel has decided to award $250k for this report
#44He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...
Re: The Chrome VRP Panel has decided to award $250k for this report
#45"Decent." was the first word that came into my mind. After a second, I realized that 250,000 USD ist basically 0.00022 % of Alphabet's (Google's?) annual net income [0]. A life changing amount of money for an individual, but nothing more than a small blip on Google's charts. Of course, I'm aware of "budgets" and "departments", and that one simply does not move funds between departments. And while my mind is on the ve…
Indeed, one of the great tragedies of life is that this happens. Humans cannot survive without water, yet the median water bill is $80, which is about 1% of the median household's income. People make so much money but refuse to pay for something that literally sustains their life. Join me in requiring that every household at least 10x the amount they pay for this precious water. To employees of water companies: Thank…
Re: The Chrome VRP Panel has decided to award $250k for this report
#46He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...
Why not collect from both of the sources? First collect with your black hat and then with your white.
Security services tend to anonymously report security flaws they use after use against any high value target, since they don't want the opponent using those same flaws back at them.
Re: The Chrome VRP Panel has decided to award $250k for this report
#47He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...
Why not collect from both of the sources? First collect with your black hat and then with your white.
Yes they will.
Re: The Chrome VRP Panel has decided to award $250k for this report
#48Earlier quoted context omitted.
First you compromise the renderer process via e.g. a bug in the JS engine. But even if you have native code execution in the context of the renderer process, you're still in a sandbox. The bug in the OP is for the second stage - breaking out of the sandbox. The referenced `patch.diff` is basically for simulating a compromised renderer.
Ah, so it's like a two stage rocket, this turns a small exploit into a humongous one?
Re: The Chrome VRP Panel has decided to award $250k for this report
#49Impressive. Feel like finding issues like this in such a large project is like looking for a needle in a haystack
I feel like it's the opposite. In a huge project there's bound to be many weird interactions between components, and it's about picking the important/security relevant ones and finding edge cases. In this case the focus was on the interaction between the renderer process and the broker. That forms a security boundary so it makes sense to focus your efforts there - google will pay for such exploits since they can in t…
I read from one security researchers somewhere that professionals wouldn’t find enough bug bounty worthy problems in high enough frequency to pay their bills. So they’ll sometimes treat things like this more as a supplement to promote their CV rather than as a job itself.
Re: The Chrome VRP Panel has decided to award $250k for this report
#50Sandbox escape with high-quality report in Chrome: $250k [1], yet Mozilla will offer you $20k [2] for that... [1] https://bughunters.google.com/about/rules/chrome-friends/574... [2] https://www.mozilla.org/en-US/security/client-bug-bounty/
According to Wikipedia, that's 0.012% of their net income. [0] While I'm being told in the comments that this is not the way to look at it, it means that this is, percentage wise, 50x the amount that Google is paying. Sounds fine to me. [0]: https://en.wikipedia.org/wiki/Mozilla_Corporation //Edit: Had a typo in my percentage. 20.000 of 157.000.000 is, indeed, 0.012% - that makes it 50x the amount of Google's percent…
How much of the Mozilla foundation's income goes into product development nowadays?