8 ms·
"Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page.
by mpeg 8mo ago
"Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
That's pretty bad! I wonder what kind of bounty went to the researcher.
- waynesonfire 8mo ago"Actually, you forgot Brave."
- mpeg 8mo agoI quoted directly from NIST, there's many other browsers and non-browsers that use chromium
- waynesonfire 8mo agoIt was intended as a joke reference to the 2004 Kerry / Bush debate. It's not a coincidence that Google would leave off an ad-blocking variant of Chrome.
- order-matters 8mo agothey listed the top 3 most popular chromium browsers, covering 90%+ of chromium users
- ipaddr 8mo agoBut not 90% of users here.
- pear01 8mo agodid you also take poland being omitted to be some sort of conspiracy? seems you missed the point of why that "Actually, you forgot..." moment became such a punchline. Like it or not Brave is a very niche browser with rather insignificant market share why you would expect them to be mentioned in the first place is entirely lost on me. there are dozens of chromium forks also with under 1% market share, should we be forced to mention them all?
- waynesonfire 8mo agoIt semeed to me like an obvious telegraph of bias. I understand the meme very well. What made the Poland meme was that Poland's membership in the coalition was irrelevant to the "grand coalition" narrative--Kerry's omission of Poland is therefore in the same vein as Google's.
- pear01 8mo agoIf you understand the meme "very well" then what do you mean by "telegraph of bias"? The joke is that Poland was largely irrelevant compared to the United States in that context, making Bush's (and your own) comeback laughable. It's not a conspiracy or "bias" that you don't mention Poland or the other members of the coalition for the same reason you don't mention every single Chromium fork, because realistically its not relevant. And just to get ahead of it, I sure hope you are not tempted to make an equivalency between a Polish death and not mentioning Brave in a vain effort to resuscitate your position. Because not only would that be extremely misplaced given you provided the clumsy reference in the first place, but Kerry's point in of itself doesn't negate that. You can both understand any life lost is a tragedy while also understand there is no "grand coalition" when the United States shares > 90% of the costs. Just like (even though again, these things should not be compared, but just to indulge the comparison you yourself invoked) maybe Brave or some other under 1% fork does some good things, but that doesn't mean it is relevant to list them for this kind of announcement or any time chromium comes up. Honestly I have no idea what you're trying to say. Following the allusion to the meme you brought up would be to realize that saying "Actually, you forgot about Brave" is a funny thing to say because its irrelevant and thus a dumb thing to say. It seems you understand there is a joke being made here but perhaps don't realize you're on the wrong side of it.
- sumtechguy 8mo agoSteam and VSCode pop into my mind.
- bicepjai 8mo agoSo basically Firefox is not affected ?
- jsheard 8mo agoFirefox and Safari are fine in this case, yeah.
- DetroitThrow 8mo agoIt's pretty hard to have an accidental a use after free in the FireFox CSS engine because it is mostly safe Rust. It's possible, but very unlikely.
- topspin 8mo agoThat came to my mind as well. CSS was one of the earliest major applications of Rust in FireFox. I believe that work was when the "Fearless Concurrency" slogan was popularized.
- koito17 8mo agoYup. To this day, Firefox remains the only browser with a *parallel* CSS engine. Chromium and WebKit teams have considered this and decided not to pursue since it's really easy to get concurrency wrong. If I recall correctly, the CSS engine was originally developed for Servo and later embedded into Firefox.
- moritzwarhier 8mo agoFirefox and Safari developers dared the Chromium team to implement :has() and Houdini and this is the result! /s
- hdgvhicv 8mo agoThe listed browsers are basically skins on top of the same chromium base. It’s why Firefox and Safari as so important despite HN’a wish they’d go away.
- duozerk 8mo ago> That's pretty bad! I wonder what kind of bounty went to the researcher. I'd be surprised if it's above 20K$. Bug bounties rewards are usually criminally low; doubly so when you consider the efforts usually involved in not only finding serious vulns, but demonstrating a reliable way to exploit them.
- salviati 8mo agoI think a big part of "criminally low" is that you'll make much more money selling it on the black market than getting the bounty.
- consumer451 8mo agoI am far from the halls of corporate decision making, but I really don't understand why bug bounties at trillion dollar companies are so low.
- arcfour 8mo agoBecause it's nice to get $10k legally + public credit than it is to get $100k while risking arrest + prison time, getting scammed, or selling your exploit to someone that uses it to ransom a children's hospital?
- kspacewalk2 8mo agoIs it in fact illegal to sell a zero day exploit of an open source application or library to whoever I want?
- IggleSniggle 8mo agoDepends. Within the US, there are data export laws that could make the "whoever" part illegal. There are also conspiracy to commit a crime laws that could imply liability. There are also laws that could make performing/demonstrating certain exploits illegal, even if divulging it isn't. That could result in some legal gray area. IANAL but have worked in this domain. Obviously different jurisdictions may handle such issues differently from one another.
- pjmlp 8mo agoYeah, but lets keeping downplaying use-after-free as something not worth eliminating in 21st century systems languages.
- pheggs 8mo agoI love rust but honestly I am more scared about supply chain attacks through cargo than memory corruption bugs. The reason being that supply chain attacks are probably way cheaper to pull off than finding these bugs
- staticassertion 8mo agoGoogle already uses `cargo-vet` for rust dependencies.
- pheggs 8mo agothats good, but it wont eliminate the risk
- staticassertion 8mo agoNothing eliminates the risk but it is basically a best-in-class solution. If your primary concern is supply chain risk, there you go, best in class defense against it. If anything, what are you doing about supply chain for the existing code base? How is cargo worse here when cargo-vet exists and is actively maintained by Google, Mozilla, and others?
- pheggs 8mo agotrue, but rusts success in creating an easy to use dependency manager is the curse. In general rust software seems to use a larger amount of dependencies than c/c++ due to that, where each is at risk of becoming an attack vector. my prediction is that we will see some abuse of this in future, similar to what npm experienced
- deanc 8mo agoPresumably this affects all electron apps which embed chrome too? Don’t they pin the chrome version?
- comex 8mo agoYes, but it's only a vulnerability if the app allows rendering untrusted HTML or visiting untrusted websites, which most Electron apps don't.
- mixologic 8mo agopretty sure I've had slack show me whole web pages without kicking me out to the mobile browser.
- spartanatreyu 8mo agoExcept: Spotify (through ads), Microsoft Teams (through teams apps), Notion (through user embedded iframes), Obsidian (through user embedded iframes), VSCode (through extensions), etc...
- seanhunter 8mo agoLots of apps like slack and discord will show you an opengraph preview of a website if you post a link. I could of course be wrong but expect you could craft an exploit that just required you to be able to post the link - then it it would render the preview and trigger the problem. Secondly as a sibling pointed out lots of apps have html ads so if you show a malicious ad it could also trigger. I’m old enough to remember the early google ads which which google made text-only specifically because google said that ads were a possible vector for malware. Oh how the turns have tabled.
- letrix 7mo agoOpen Graph is a standard for HTML meta tags. Apps like Slack and Discord just make a request to the given URL (locally or in their servers) and read those tags. Then they choose how that information should be displayed. No HTML injection occurs. https://ogp.me https://ogp.me
- StilesCrisis 8mo agoIt would also require a sandbox escape to be a meaningful vulnerability. Unfortunately, "seen in the wild" likely means that they _also_ had a sandbox escape, which likely isn't revealed publicly because it's not a vulnerability in properly running execution (i.e., if the heap were not already corrupted, no vulnerability exists).
- staticassertion 8mo agoI'd bet that the sandbox escape is just in the underlying operating system kernel and therefor isn't a matter for Chromium to issue a CVE.