3 ms·
Practically speaking there's probably not a ton of difference. ITW exploits are pretty uncommon for both, and they're typically somewhat targeted. I haven't pai
by staticassertion 4y ago
Practically speaking there's probably not a ton of difference. ITW exploits are pretty uncommon for both, and they're typically somewhat targeted. I haven't paid attention in years for this reason, but I'd guess that Chrome is ahead - mitigation techniques like site isolation are quickly improving in it and were adopted earlier as well.
In general my recollection is that Chrome splits up more of its components. It sounds like, based on this post, the gpu process is now separated and there's sandboxing efforts going into that, but I'm pretty sure Chrome has had that for years now.
- rockdoe 4y agoFirefox has also had this for over 5 years: https://www.mozilla.org/en-US/firefox/53.0a2/releasenotes/ https://www.mozilla.org/en-US/firefox/53.0a2/releasenotes/ The current mitigations seem to be doubling-down on getting rid of C++ memory safety errors (still the main source of security holes), with Mozilla pulling the Rust and WebAssembly card. So there's some divergence here, rather than parallel paths with one ahead.