5 ms·
That's kinda-sorta what they all do already. Not full OS-level VM abstraction, but surprisingly close to it. Exploits like this need to be paired with sandbox-e
by Chabsff 3y ago
That's kinda-sorta what they all do already. Not full OS-level VM abstraction, but surprisingly close to it. Exploits like this need to be paired with sandbox-escaping in order to do damage beyond the current browsing session (which VMs wouldn't help with in the first place). And the distinction between sandbox-escaping and VM-escaping is rather thin.
- Syonyk 3y ago> And the distinction between sandbox-escaping and VM-escaping is rather thin. Eh, I think it's a good bit harder to escape a HVM isolated virtual machine than a sandbox. At least, I'm not aware of many cross-Xen VM escapes.
- lmm 3y agoThere used to be dozens of them at any given time; maybe they're a bit rarer now that cloud providers have been banging on them for a while.
- taway1237 3y agoThere's a huge difference. Browser sandboxes are not "real" VMs and share a kernel. And in case of Chromium it's enough to read a few bytes from another process (token) to escape.
- nolist_policy 3y agoCan you elaborate on that? What do tokens have to do with breaking out of a sandbox?
- Chabsff 3y agoYes, I should have added that I'm referring specifically to the scenario OP is suggesting, which would require a host <-> client IPC channel, opening up the VM to similar attack vectors to a sandbox.