01.01.2020»»среда

Has Google Chrome Been Hacked

01.01.2020

An interesting hack happened in 2014. This is George Francis Hotz a.k.a. You can thank him for jailbreaking iPhones. You may also remember he jailbroke the PS3 system and was sued by Sony resulting in him agreeing not to tamper with Sony software. In 2014 he found an exploit in google chrome and was awarded $150,000 as a bounty. GOOGLE has warned users that billions of passwords – and hundreds of thousands of username and password combinations – have been hacked.

Security researchers from the French pen-testing firm VUPEN have successfully hacked Google's Chrome browser with what is being described as a sophisticated exploit that bypasses all security features including ASLR/DEP and Chrome's heralded sandbox feature.

VUPEN released a video of the exploit in action to demonstrate a drive-by download attack that successfully launches the calculator app without any user action.

The exploit shown in this video is one of the most sophisticated codes we have seen and created so far as it bypasses all security features including ASLR/DEP/Sandbox (and without exploiting a Windows kernel vulnerability), it is silent (no crash after executing the payload), it relies on undisclosed (0day) vulnerabilities discovered by VUPEN and it works on all Windows systems (32-bit and x64).

Google Chrome Browser

VUPEN, which sells vulnerability and exploit information to business and government customers, does not plan to provide technical details of the attack to anyone, including Google.

Palm hotsync software windows 10. In the video (see below), the company demonstrates the exploit in action with Google Chrome v11.0.696.65 on Microsoft Windows 7 SP1 (x64). The user is tricked into visiting a specially crafted web page hosting the exploit which executes various payloads to ultimately download the Calculator from a remote location and launch it outside the sandbox (at Medium integrity level).

Google Chrome Free Download

While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own contest during the last three years, we have now uncovered a reliable way to execute arbitrary code on any default installation of Chrome despite its sandbox, ASLR and DEP, VUPEN explained.

VUPEN made headlines in March this year when a team of its researchers hacked into Apple's MacBook via a Safari vulnerability to win the CanSecWest PWN2Own contest.

Can Google Chrome Be Hacked

Related Topics:

Enterprise Software Digital Transformation Innovation Thought Leadership Tech Industry