Earlier quoted context omitted.
While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?
ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
Actively exploited sandbox RCE in all Chromium versions
51–60 of 510 posts
Re: Actively exploited sandbox RCE in all Chromium versions
#52Earlier quoted context omitted.
Which browser has a better security track record?
Vanadium makes improvements on Chromium. https://grapheneos.org/features#vanadium
Re: Actively exploited sandbox RCE in all Chromium versions
#53Earlier quoted context omitted.
While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?
You let the market decide. Google could purchase the bugs on the same market blackhats do.
Re: Actively exploited sandbox RCE in all Chromium versions
#54Let's take a moment to talk about the monetary value of this vulnerability. According to the Chrome release page ( https://chromereleases.googleblog.com/2026/09/stable-channel... ), Google paid a researcher $1000 for ethically reporting this. The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? H…
The problem is they are being flooded with both fake AND real disclosures. Imagine if they tried to pay out $250,000 or more per bug? Would the cost be worth it? Maybe, but shareholders may not be pleased... Unless they viewed it as insurance against it being more financially sound for the finder to sell the exploit on the gray or black market instead...
Re: Actively exploited sandbox RCE in all Chromium versions
#55Re: Actively exploited sandbox RCE in all Chromium versions
#56Earlier quoted context omitted.
ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
it seems unlikely google's lawyers would go for this
Re: Actively exploited sandbox RCE in all Chromium versions
#57Earlier quoted context omitted.
ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
it seems unlikely google's lawyers would go for this
Re: Actively exploited sandbox RCE in all Chromium versions
#58Earlier quoted context omitted.
Which browser has a better security track record?
Firefox with uBlock Origin. It’s astonishing how many exploits uBO stops before they ever reach your browser engine. It’s the antivirus of the 2020s.
Re: Actively exploited sandbox RCE in all Chromium versions
#59Earlier quoted context omitted.
While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?
ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
Remember that you can sell the same vulnerability to multiple people: it's software you can copy.
Re: Actively exploited sandbox RCE in all Chromium versions
#60Earlier quoted context omitted.
You let the market decide. Google could purchase the bugs on the same market blackhats do.
In the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.
Isn't that a good thing?
> However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.
If Google can find all the bugs nowadays, presumably with AI, why still pay a bug bounty? At least by this logic, bug bounties make less sense now.