3 ms·
> Has there ever been a widespread instance where users were infected with malware from a Chrome exploit? I haven't heard of one yet. Maybe not widespread atta
by favourable 4y ago
> Has there ever been a widespread instance where users were infected with malware from a Chrome exploit? I haven't heard of one yet.
Maybe not widespread attacks, but the Chrome team regularly see 0days being actively exploited in the wild, I imagine as rare and isolated incidents instead of mass pwning billions of users. For some exploits to work you have to visit a carefully crafted page that has the payload in it. And that's not easy to do at scale. You'd have to cajole millions (billions?) of people into navigating to a specific URL. Also I imagine you don't hear about these exploits because the actors would have good op-sec and keep all their data gathering secret.
- TheKarateKid 4y agoOf course. But my point is that the old days where visiting a very reputable website and being infected with a drive-by exploit delivered via an ad seem to finally be over.