Live data from Hacker News

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov

51–60 of 510 posts

Re: Actively exploited sandbox RCE in all Chromium versions

#51
post #39

Earlier quoted context omitted.

While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?

ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.

it seems unlikely google's lawyers would go for this

Re: Actively exploited sandbox RCE in all Chromium versions

#52
post #22

Earlier quoted context omitted.

Which browser has a better security track record?

Vanadium makes improvements on Chromium. https://grapheneos.org/features#vanadium

Most of those are just changing flags, not really unique development. Like "disable JIT" is a Chromium flag. "Zero-init everything" is a Clang flag.

Re: Actively exploited sandbox RCE in all Chromium versions

#53

Earlier quoted context omitted.

While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?

You let the market decide. Google could purchase the bugs on the same market blackhats do.

In the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.

Re: Actively exploited sandbox RCE in all Chromium versions

#54
post #29

Let's take a moment to talk about the monetary value of this vulnerability. According to the Chrome release page ( https://chromereleases.googleblog.com/2026/09/stable-channel... ), Google paid a researcher $1000 for ethically reporting this. The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? H…

The problem is they are being flooded with both fake AND real disclosures. Imagine if they tried to pay out $250,000 or more per bug? Would the cost be worth it? Maybe, but shareholders may not be pleased... Unless they viewed it as insurance against it being more financially sound for the finder to sell the exploit on the gray or black market instead...

They should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $10K base. That would net a researcher ~$88K for this specific bug (8.8 severity).

Re: Actively exploited sandbox RCE in all Chromium versions

#56
post #51
post #39

Earlier quoted context omitted.

ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.

it seems unlikely google's lawyers would go for this

well that's why setting it up is hard, because you would want to do it in a way that what they want doesn't matter.

Re: Actively exploited sandbox RCE in all Chromium versions

#57
post #51
post #39

Earlier quoted context omitted.

ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.

it seems unlikely google's lawyers would go for this

Maybe some code is so important and heavily trafficked it becomes a public works project, and various legs can bid for pieces of the project, line how all infrastructure works.

Re: Actively exploited sandbox RCE in all Chromium versions

#58
post #31
post #22

Earlier quoted context omitted.

Which browser has a better security track record?

Firefox with uBlock Origin. It’s astonishing how many exploits uBO stops before they ever reach your browser engine. It’s the antivirus of the 2020s.

Brave would be a much better option if you want security and good adblocking.

Re: Actively exploited sandbox RCE in all Chromium versions

#59
post #39

Earlier quoted context omitted.

While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?

ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.

What kind of auction would you like to run?

Remember that you can sell the same vulnerability to multiple people: it's software you can copy.

Re: Actively exploited sandbox RCE in all Chromium versions

#60
post #53

Earlier quoted context omitted.

You let the market decide. Google could purchase the bugs on the same market blackhats do.

In the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.

> In the past I would have thought this would incentivize finding bugs that might never be found.

Isn't that a good thing?

> However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.

If Google can find all the bugs nowadays, presumably with AI, why still pay a bug bounty? At least by this logic, bug bounties make less sense now.

Post reply on HN