Earlier quoted context omitted.
While I agree 1000 is hilariously low for this, worth is hard to quantify. Do you pay what it could theoretically cost your company? the amount the top bidding bad actor would be willing to pay?
You let the market decide. Google could purchase the bugs on the same market blackhats do.
Actively exploited sandbox RCE in all Chromium versions
101–110 of 524 posts
Re: Actively exploited sandbox RCE in all Chromium versions
#102Normalising running arbitrary code delivered over the internet (in the form of JavaScript and WASM), as a necessary condition for accessing most web pages may not have been one of the best decisions we have made.
Re: Actively exploited sandbox RCE in all Chromium versions
#103Re: Actively exploited sandbox RCE in all Chromium versions
#104Earlier quoted context omitted.
I remember noticing this shift in nerd culture. In the early 2000s, it was common for people to say on places like Slashdot that they don't trust JavaScript and run their browser with it off. In the early 2010s, I noticed HN commenters thought this was insane, tinfoil hat type thinking.
It became insane because nothing bloody worked without Javascript some time in the early 2010s. Like cellphones, javascript became necessary if you want to use webmail, access your bank's website, or whatever.
It's the classic thing. Across every gdmf metric, excluding with "true empathy", no one *gives a fuck* until it affects them, or someone within (1-3) degrees of separatation. And having broad empathy is generally a good way to get yourself labeled/astrocized: both about as obvious "compriate" and obvious "adversary".
Re: Actively exploited sandbox RCE in all Chromium versions
#105Let's take a moment to talk about the monetary value of this vulnerability. According to the Chrome release page ( https://chromereleases.googleblog.com/2026/09/stable-channel... ), Google paid a researcher $1000 for ethically reporting this. The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? H…
> But at the same time, if someone submits a critical issue like this, it makes sense to pay them what the bug's actually worth. I'd point out that part of the reason the grey and black market pays so well is because it is that type of market. You have to pay people extra to look past their morals and a risk premium against potential reputational and legal consequences. That said, the gap is probably not just that.
Someone could sell it on the black market, sell it to Google, or just move on with their life and not sell it.
I don't know what this is worth on the black market, maybe I'd be scammed by even trying to sell it. Maybe I don't want to be a bad person. These are all things that go into the prices
Re: Actively exploited sandbox RCE in all Chromium versions
#106Normalising running arbitrary code delivered over the internet (in the form of JavaScript and WASM), as a necessary condition for accessing most web pages may not have been one of the best decisions we have made.
I remember noticing this shift in nerd culture. In the early 2000s, it was common for people to say on places like Slashdot that they don't trust JavaScript and run their browser with it off. In the early 2010s, I noticed HN commenters thought this was insane, tinfoil hat type thinking.
Re: Actively exploited sandbox RCE in all Chromium versions
#107Let's take a moment to talk about the monetary value of this vulnerability. According to the Chrome release page ( https://chromereleases.googleblog.com/2026/09/stable-channel... ), Google paid a researcher $1000 for ethically reporting this. The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? H…
It sounds insultingly low, yeah. I'm trying to imagine why they would pay so little. The only two reasons I can think of are either (a) they were already aware of it and fixing it, and therefore the report didn't really change much, or (b) it requires an unusual configuration or otherwise rare opportunity to that makes it impractical to exploit most users. Really curious to see what the issue was whenever it gets mad…
Re: Actively exploited sandbox RCE in all Chromium versions
#108Earlier quoted context omitted.
RCE inside sandbox, so requires chaining with another 0day.
what is online ad networks for $100, alex
My read of Google's disclosure is that there is likely no known escape from the sandbox. I don't agree this would be reported this way just because "user action" like "using web browser" is required. Even if this individual CVE is correctly an 8.8 there would be a critical assessment of a known chain. The only reason there wouldn't be, would be if the other vulnerability is known to Google but has no patch yet.
Re: Actively exploited sandbox RCE in all Chromium versions
#109Earlier quoted context omitted.
I remember noticing this shift in nerd culture. In the early 2000s, it was common for people to say on places like Slashdot that they don't trust JavaScript and run their browser with it off. In the early 2010s, I noticed HN commenters thought this was insane, tinfoil hat type thinking.
It became insane because nothing bloody worked without Javascript some time in the early 2010s. Like cellphones, javascript became necessary if you want to use webmail, access your bank's website, or whatever.
Re: Actively exploited sandbox RCE in all Chromium versions
#110Earlier quoted context omitted.
You let the market decide. Google could purchase the bugs on the same market blackhats do.
Blackhat markets will always be able to pay better. Selling to Google though you aren't chancing jail time.
... than Google?
> Selling to Google though you aren't chancing jail time.
Why would you go to jail for selling a vulnerability? It's free speech.