38 ms·
I also wonder if they publish proof of concepts for security bugs they refuse to fix (e.g. in Android 4.3).
by xaqfox 12y ago
I also wonder if they publish proof of concepts for security bugs they refuse to fix (e.g. in Android 4.3).
- giovannibajo1 12y agoThey said they also investigate on Android, but they haven't yet published a single vulnerability for it, as far as I can tell.
- ikonst 12y agoRight on their blog, though it's a guest post but they don't seem to have anything against it: http://googleprojectzero.blogspot.com/2015/01/exploiting-nvmap-to-escape-chrome.html http://googleprojectzero.blogspot.com/2015/01/exploiting-nvm...
- giovannibajo1 12y agoYes, it's a guest post. What I said is that, while in theory they said they will research all major OSs (including Android, which is by far the most common mobile OS), they have yet to publish a single vulnerability as a result of their research.
- patrickaljord 12y agoMaybe they do publish them but they are all fixed before the 90 windows passes so they don't have to be disclosed their. You still go to git.chromium.org and aosp's git see the daily security/improvement patches that go there.
- giovannibajo1 12y agoThe disclosure window is typically for fixes released to end-users, not just fixed by vendors. This is also what was enforced with MS last round, where they had a fix ready but couldn't get it to pass QA and being released before the 90-days window expired.
- Oletros 12y agoWas the security bug discovered by Project Zero team?
- chc 12y agoThese bugs appear to be for Yosemite, so they might only look at bugs present in the latest version of the software.
- izacus 12y agoI doubt they're wasting time with bugs in OS X 10.5 either.