Google’s Project Zero discloses Windows 0day that’s been under active exploit
1–10 of 10 posts
Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#2Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#3Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#4Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#5Seems like they conveniently waited to fix Chrome bug before going ballistic at Microsoft.
> In keeping with long-standing policy, Google’s vulnerability research group gave Microsoft a seven-day deadline to fix the security flaw because it’s under active exploit. Normally, Project Zero discloses vulnerabilities after 90 days or when a patch becomes available, whichever comes first.
In addition, the two bugs appear to be unrelated other than being used as part of the same attack chain. The Chrome/FreeType vulnerabilities were reported on 2020-10-19 [0, 1], while the Windows vulnerability was reported on 2020-10-22 [2]. The Chrome team released a fix for their bug the day after the it was reported [3], while Microsoft is either still working on fixing the bug or is waiting for Patch Tuesday.
[0]: https://bugs.chromium.org/p/chromium/issues/detail?id=113996...
[1]: https://savannah.nongnu.org/bugs/?59308
[2]: https://bugs.chromium.org/p/project-zero/issues/detail?id=21...
[3]: https://twitter.com/benhawkes/status/1318640422571266048
Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#6Seems like they conveniently waited to fix Chrome bug before going ballistic at Microsoft.
Project Zero's disclosure policy as described in the article appears to leave little room, if any, for the bias you appear to be implying: > In keeping with long-standing policy, Google’s vulnerability research group gave Microsoft a seven-day deadline to fix the security flaw because it’s under active exploit. Normally, Project Zero discloses vulnerabilities after 90 days or when a patch becomes available, whichever…
Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#7Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#8Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#9Showing more adversaries how to make exploits right now doesn't seem like a great idea?
Re: Google’s Project Zero discloses Windows 0day that’s been under active exploit
#10Did they include a proof of concept in the disclosure even though the Google patch has only been out for a week and the Microsoft patch is not yet available? Showing more adversaries how to make exploits right now doesn't seem like a great idea?
This isn’t always true: sometimes knowing where to look is the easy part, and crafting a working exploit is the hard part. I don’t get the impression that’s the case here.