3 ms·
New Chrome Zero-Day
- maerF0x0 7y agoI would suggest we put the date in these kind of 0 day titles. Nov 4 in this case...
- maxmcd 7y agoPrevious discussion: https://news.ycombinator.com/item?id=21425804 https://news.ycombinator.com/item?id=21425804
- 0xdeadb00f 7y agoI'm assuming this doesn't affect Chromium, or Chromium(-based) browsers on Android then? Seeing as it isn't mentioned.
- mark-r 7y agoThe article specifically mentions that it was discovered on Windows, but that doesn't mean some variation couldn't exist for other platforms.
- 0xdeadb00f 7y agoI meant more along the lines of: is this a Chrome specific vulnerability or is the vuln apparent in Chromium and thus are all Chromium-based browsers (on any platform) affected?
- NikolaeVarius 7y agoWas already patched on Oct 31 https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html https://chromereleases.googleblog.com/2019/10/stable-channel...
- andrewstuart 7y agoWhy would cybercriminals not just report the bug and pick up the cash from Google? Is it genuinely that much more lucrative to exploit it?
- imposterr 7y agoYou can only sell to Google once. You can sell it to different exploit houses many times. But also historically, some places pay in the several hundred thousand compared to tech companies that pay in the tens of thousands. So even if they only sell it once, they can make more.
- wnevets 7y ago>Why would cybercriminals not just report the bug and pick up the cash from Google? Probably because they're not the ones actually finding the bugs.
- lawnchair_larry 7y agoIt isn’t cybercriminals. Cybercriminals pretty much never have top tier 0day. This one is North Korean intelligence, and they get far more value out of it than Google is willing to pay.
- thephyber 7y agoThe CVE is still embargoed[1] as of the time of this comment. =/ [1] https://nvd.nist.gov/vuln/detail/CVE-2019-13720 https://nvd.nist.gov/vuln/detail/CVE-2019-13720