Earlier quoted context omitted.
In the future we can ask that your JaveScript and Wasm comes with a proof of being benign.
Prior art: the evil bit https://datatracker.ietf.org/doc/html/rfc3514
Actively exploited sandbox RCE in all Chromium versions
351–360 of 527 posts
Re: Actively exploited sandbox RCE in all Chromium versions
#352For what is this exploited in the wild when it doesn't include a sandbox escape? Is this chained with n-days?
Re: Actively exploited sandbox RCE in all Chromium versions
#353Earlier quoted context omitted.
What kind of auction would you like to run? Remember that you can sell the same vulnerability to multiple people: it's software you can copy.
Maybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.) $1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?). Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty r…
Negotiating with terrorists or black mailers is a bad idea.
Re: Actively exploited sandbox RCE in all Chromium versions
#354Earlier quoted context omitted.
Or disable JS altogether, and enjoy many sites working much quicker. Many others fail & need to be selectively allowed, but it's been worth it.
If by quicker you mean blank content, I'll agree, it is worth it.
Re: Actively exploited sandbox RCE in all Chromium versions
#355Earlier quoted context omitted.
I'm just saying it's more evidence that Google should be broken up.
How would you break up Google that would make browsers more secure?
This should have been done a long time ago.
Firefox, and the browser market would be much more healthy. Btw, Microsoft, Apple, Facebook, now even Twitter/SpaceX and all of these should have been forced the same way. And of course not just in this field, but all of them, like oil companies. They can pivot, of course, with some grace period, but that would mean giving up something at the end.
And if we are there, we can abolish most of trade secrecy too, which exists only to keep up the status quo while hindering progress.
Re: Actively exploited sandbox RCE in all Chromium versions
#356Is the HN title true that it affects all "all Chromium versions"? Per OP link, it only affects Chrome versions prior to .82; .82 was released as stable 2 days ago. [1] (HN title also does not match the original title, which is the CVE ID -- not particularly intuitive.) [1] https://chromereleases.googleblog.com/2026/09/stable-channel...
Re: Actively exploited sandbox RCE in all Chromium versions
#357Re: Actively exploited sandbox RCE in all Chromium versions
#358Let's take a moment to talk about the monetary value of this vulnerability. According to the Chrome release page ( https://chromereleases.googleblog.com/2026/09/stable-channel... ), Google paid a researcher $1000 for ethically reporting this. The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? H…
why? google removed don't be evil off their charter a long time ago. why shouldn't security researchers also seek to maximize profits?
Re: Actively exploited sandbox RCE in all Chromium versions
#359Earlier quoted context omitted.
If the vulnerability is already being exploited in the wild --- as in, it's a vector people already know about and are tracking --- it's possibly not worth much at all. Vulnerability valuations depend heavily on the lifespan of the vulnerability; payments on black market are tranched (explicitly or less explicitly, as with "maintenance payments") based on whether they're patched. Further: a vulnerability is probably…
Knowing the vulnerability, creating an exploit might be relatively easy now that we have AI to figure the boring stuff out.
Re: Actively exploited sandbox RCE in all Chromium versions
#360Normalising running arbitrary code delivered over the internet (in the form of JavaScript and WASM), as a necessary condition for accessing most web pages may not have been one of the best decisions we have made.