Skip to main content

Pwn2Own 2012: Google Chrome first to fall

posted onMarch 7, 2012
by l33tdawg

At last year’s CanSecWest Pwn2Own hacker contest, Google Chrome was the only browser left standing.  This year, Chrome was the first to fall, thanks to an impressive exploit from a team of French hackers.

VUPEN, the controversial company that sells vulnerabilities and exploits to government customers, deliberately took aim at Chrome this year to send a simple message: no software is unbreakable if hackers have enough motivation to prepare and launch an attack.

VUPEN co-founder and head of research Chaouki Bekrar and his team used a pair of zero-day vulnerabilities to take complete control of a fully patched 64-bit Windows 7 (SP1) machine.   As part of the new competition format, VUPEN will earn 32 points for the successful Chrome exploit. In an interview, Bekrar said his team worked for about six weeks to find the vulnerabilities and write the exploits.  ”We had to use two vulnerabilities. The first one was to bypass DEP and ASLR on Windows and a second one to break out of the Chrome sandbox.”

Source

Tags

Chrome Google Security Hackers CanSec. Pwn2Own

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th