3 ms·
Yes, it does, at least if you go by how much money the sketchy vulnerability brokers are offering to pay. On https://zerodium.com/program.html https://zerodium.
by jimrandomh 4y ago
Yes, it does, at least if you go by how much money the sketchy vulnerability brokers are offering to pay. On https://zerodium.com/program.html https://zerodium.com/program.html a Chrome RCE+LPE is "Up to $500k", while the other browsers are all less.
- leoc 4y agoI guess that that partly reflects its greater market share though.
- guilhas 4y agoAnd that attackers also focus more on the higher market share Chrome is also not immune, very recently had a serious flaw "actively exploited" https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-zero-day-used-in-attacks/ https://www.bleepingcomputer.com/news/security/google-chrome...
- mlinksva 4y agoI wonder how those $ amounts are arrived at, I don't see in FAQ. Maybe a third party study of potential factors and prices (quick search I'm not finding anything promising)? Surely market share/adoption is very significant, but something else must explain e.g., 2.5x more for Apache RCE than Nginx RCE?
- Hackbraten 4y agoThere are several factors that may affect per-app supply and demand. - How expensive is it to discover a new vulnerability in a given app? (This may depend on code base maturity but also on choice of programming language, its inherent memory safety, and supply chain.) - What privileges does a typical installation of the app grant once RCE is achieved? - How hard is it to write a working exploit for a newly-discovered vulnerability, taking into account the security architecture that protects the app? - Given a zero-day exploit, how many times will you have the opportunity to use it? How quickly will other parties discover it, is the vendor willing to provide patches, how long it is going to take, how much do the updates cost, and how difficult is it to upgrade the software in the field? - Apps and computers tend to come in packs, and attackers love to move laterally. What opportunities would an attacker gain from lateral movement after gaining persistence in a given system? - Market share and adoption may be skewed, as attackers may be interested in specific targets such as journalists or politicians, who may form a specific demographic with particular adoption rates, which can differ from those of the general population.
- weaksauce 4y agohttps://gs.statcounter.com/browser-market-share https://gs.statcounter.com/browser-market-share if you believe those numbers... 64% vs 3% market share. of course something that impacts 64% of the internet will be more valuable.
- rockdoe 4y agoWould the majority of the current "desktop" software actually being outdated Chromium/Electron/CEF stuff factor into this too?
- weaksauce 4y agoI really doubt it. https://www.w3schools.com/browsers/default.asp https://www.w3schools.com/browsers/default.asp that's another sampling of actual web visits. though it skews more tech oriented of course so that's going to be away from safari/ie and more toward firefox and chrome.
- rockdoe 4y agoI mean in the rewards. A lot of those "desktop apps" have embedded "WebViews", if you know what I mean, which would effectively be running outdated Chrome versions, which would be easier to exploit than the real thing.
- black_puppydog 4y agoAhhh, the breath of fresh air coming from a truly free market doing what markets do best: processing information in the face of uncertainty to the benefit of all! Don't you feel the soft touch of the invisible hand, gently working to raise the tide of security for all? /s