Google Chrome compromised in five minutes at Pwn2Own

updated 09:15 pm EST, Wed March 7, 2012

 

Chrome security breached almost immediately


Google saw an end to a brief streak on Wednesday after CanSecWest's organizers confirmed that Chrome had been hacked during the Pwn2Own contest. Team Vupen exploited a security hole in the browser within five minutes of the contest's start. The group will be getting at least a $60,000 prize, funded partly by Google itself, as well as 32 points in the still-ongoing contest; it had already found two more vulnerabilities in software at the conference in intervening hours.

Exact details of the hole weren't detailed, but it was a zero-day exploit that successfully escaped Google's sandboxing and ran code.

The hack was prepared in advance and was likely helped by Google's own willingness to add significantly to the prize pool to test Chrome. It nonetheless undermines Google's insistence that Chrome is safe and shows it to not necessarily be safer in the real world than previous Pwn2Own targets like Safari. Google was one of the first to implement sandboxing, where any breach in a given browser tab or plugin is supposed to be blocked from compromising other parts, but it's now proven that the practice isn't a guarantee against exploits.

Most other browsers now have at least some form of sandboxing, whether for plugins or browser tabs.


By Electronista Staff

Post tools:

TAGS :  

industry, security, Google, hacks, Safari, Apple, Chrome, Pwn2Own
toggle

Previous Comments

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

Sponsor

Recent Reviews

Logitech FabricSkin Keyboard Folio for iPad

Since the fourth-generation iPad didn't evolve much over its predecessor, the market for iPad accessories has remained somewhat static ...

Huawei Ascend Mate

The Huawei Ascend Mate is a phone that fits the screen-size gap between the 4 to 5-inch smartphone and the seven-inch or more tablet, ...

MaxUpgrades MaxConnect for 2006-2008 Mac Pro

Nobody outside of Cupertino's privileged bunch knows the future of the Mac Pro line for sure. Despite Apple's reluctance to tell us wh ...

Sponsor

 
toggle

Popular News