VUPEN Security pwns Google Chrome
French security research group, VUPEN, announced earlier today that they have managed to subvert Google Chrome's sandbox to permit execution of code.
The announcement, which is light on details, and a demo are available on VUPEN's website. The most interesting aspect of the announcement was the declaration "This code and the technical details of the underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers as part of our vulnerability research services." Apparently this list does not include Google. Definitely an interesting twist on responsible disclosure.
Update: Further details and Google's response are available on Brian Kreb's blog.
-- Rick Wanner - rwanner at isc dot sans dot org - http://namedeplume.blogspot.com/ - Twitter:namedeplume (Protected)
Comments
dsh
May 10th 2011
1 decade ago
<drumroll please>
"fix it".
Al
May 10th 2011
1 decade ago
What a bunch of assholes.
Jason
May 10th 2011
1 decade ago
Mo
May 10th 2011
1 decade ago
"Exploits for Offensive Security. Get access to weaponized and highly sophisticated exploits specifically designed for LEA and Intelligence Agencies."
In other words 'we have absolutely no interest in seeing this (alleged) vulnerability fixed'...
IByte
May 11th 2011
1 decade ago