Bug hunter hacks Chrome at CanSecWest; earns top reward from Google

Long-time Google Chrome security contributor Sergey Glazunov earns $60,000 for hacking the browser at CanSecWest

During Google's Pwnium contest at the CanSecWest security conference in Vancouver on Wednesday, Russian bug hunter Sergey Glazunov demonstrated a Chrome exploit that completely defeats the browser's much touted security sandbox.

Chrome is viewed as one of the most secure Web browsers by the security community, primarily because of its sandboxed architecture, which restricts how it interacts with the OS and significantly limits what attackers can do if they exploit a vulnerability.

A panel of security experts from Accuvant and Coverity, who analyzed the defensive capabilities of modern browsers in depth, said last week at the RSA security conference in San Francisco that Chrome's sandbox prevents processes from doing much of anything on the system.

However, there is a consensus in the security community that while sandboxing is a strong anti-exploitation mechanism, it does not provide a perfect defense and a determined attacker can theoretically defeat it, although with a lot of work.

For this year's CanSecWest conference, Google decided to run a contest called Pwnium in parallel with TippingPoint's well known Pwn2Own contest, which rewards security researchers for finding and exploiting unpatched remote code execution (RCE) vulnerabilities in browsers.

Pwnium has a maximum prize pool of US$1 million and rewards various types of Chrome exploits. The largest prize is $60,000 and is awarded to researchers who demonstrate persistent RCE exploits that target only vulnerabilities in Google Chrome's code.

The first to earn this top reward was Sergey Glazunov, a regular Chrome bug hunter, who on Wednesday, during the first day of the contest, demonstrated an exploit that completely bypassed Chrome's sandbox.

The exploit was validated by the Google Chrome team. "Congrats to long-time Chromium contributor Sergey Glazunov who just submitted our first Pwnium entry. Looks like it qualifies as a 'Full Chrome' exploit," Sundar Pichai, Google's senior vice president for Chrome, said via his Google+ account. "We're working fast on a fix that we'll push via auto-update."

Other Chrome security engineers, like Justin Schuh or Chris Evans, expressed their excitement about the exploit via Twitter. "What a great bug from Sergey. But still a whole ton of cash left, hoping for more entrants," Evans said on his Twitter feed.

Glazunov, who has earned many rewards for finding Chrome vulnerabilities in the past, wasn't at CanSecWest in person. Instead he submitted his Pwnium entry through independent security researcher Aaron Sigel.

During day one of the Pwn2Own contest, a team of researchers from French security firm VUPEN Security also managed to hack Chrome. However, Chrome's security team suspects that the researchers' exploit targeted a vulnerability in the Flash Player plug-in that comes with the browser by default.

If that's true, VUPEN's exploit would have only qualified for a Pwnium consolation prize of $20,000, had it been submitted to the contest. VUPEN didn't confirm that their Pwn2Own Chrome exploit targeted a Flash Player vulnerability, which isn't prohibited by the Pwn2Own contest rules.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Lucian Constantin

Lucian Constantin

IDG News Service
Show Comments

Essentials

Brother MFC-L3745CDW Colour Laser Multifunction

Learn more >

Mobile

Exec

Sony WH-1000XM4 Wireless Noise Cancelling Headphones

Learn more >

Budget

Back To Business Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?