What exactly does "RCE inside sandbox" describe that goes beyond "the webpage can supply arbitrary JavaScript and the JavaScript engine executes it", but is still isolated from the system?
Chrome runs webpages in individual sandbox processes with very low privileges, as a defense-in-depth strategy. It generally requires at least two exploits to actually affect a user--first, get RCE in a sandboxed process, then find a separate vulnerability that lets you escape the sandbox process entirely. For this bug to have actually been used in the wild, there was almost certainly a second bug as well.
It means it can execute native code inside the sandbox, as opposed to Javascript. While still sandboxed, this lets it access some parts of the attack surface that JS would not have been able to, some of which may have other exploits that allow escaping the rest of the way.
I think people would like to understand what the "sandbox" is here and what isolation does it provide, is it an unprivileged process? something chromium specific? a v8/JS thing? etc.
Among other things, JavaScript in the browser has no way to even express "kill PID 1234 on the user's machine" or "list the contents of `C:\Users\Documents` and upload all of the files" or "spawn cmd.exe on the user's machine". How would you even do these things if you could run any JavaScript in the browser? You can't.
However, chrome.exe itself does because it's a native application, as is the sandboxed JavaScript interpreter inside of chrome.exe.
(This is a very oversimplified explanation but I think this is the disconnect people are having)
> JavaScript in the browser has no way to even express ... "list the contents of `C:\Users\Documents` and upload all of the files"
this is besides the point, but javascript has the file system api.
anyways to your broad point, i dont think this is convincing. What's the difference between not having an api vs having an api that is disabled (e.g. the syscall exists but is filtered). Either way you are not taking the action. RCE in the sandbox is an important step in the bigger exploit chain, but not because you can express things in the traditional syscalls inside the sandbox.
Because Javascript theoretically can't just access files on disk. Control over the render would let you do that, if not for the process level sandbox, which constraints things like file access, system, calls, etc.
But the process is still more capable than the VM. The process can talk to other processes via IPC, for example.
That's why you don't go from "javascript -> computer is taken over", instead you go from "javascript -> renderer control -> computer is taken over".
because with proper code exec you can trigger other bugs to escalate beyond the sandbox, whereas with JS you'd have to find a bug to escape from JS to native
can't get a proper ios/Android RCE with just JS code exec
Memory isolation having one tab or account open on your bank and another on this page does not mean it could leak across the sandbox and steal bank account details but anything inside of your general page content can be lost
This doesn't affect the score though, the reason there's 1.2 points less than the max is because there is a Required User Interaction. The user needs to visit a specific html page.
Even with the sandbox protection layer, the rest of the parameters are maxed out.
I don't know why this is being downvoted. This is called malvertising and its one of the most significant vectors for exploiting a vulnerability like this. Its happened multiple times over the last two decades.
My read of Google's disclosure is that there is likely no known escape from the sandbox. I don't agree this would be reported this way just because "user action" like "using web browser" is required. Even if this individual CVE is correctly an 8.8 there would be a critical assessment of a known chain. The only reason there wouldn't be, would be if the other vulnerability is known to Google but has no patch yet.
Same thing happened in downtown Denver’s 16th street mall. But they didn’t reduce parking or restrict car travel like in the article. But the same result occurred. Stores have set empty for years and more are closing every week.
Its the same at most orgs. Very rare for a vuln remediation program to utilize a truly risk based approach. They would have to trawl through and understand thousands of vulns and the context of your org. There's probably a market for some tool to accomplish this if the larger players haven't attempted already.
They see their dashboard, when the number is high, they want to get the number low as fast as possible. If the number is close to zero, they want to see zero. It is that simple.
They do not care if the issue is in a piece of code that is never executed and would require full access to the machine. It is there and tool X reports it.
Even security audits are terrible, when they don't find anything major they start reporting stuff that few percent of companies have implemented just to stuff their reports, it is ridiculous.
On a headless VM, almost certainly it's not a worry, since that bug needs a physical port and the driver binding to a plugged-in device (so basically it's never reached). You could even prove it running lsmod showing the module is not loaded (so "not applicable"). Unfortunately the CVSS score doesn't carry reachability information, and not just for the kernel CVEs.
This is the rot that's happening in cybersec. Before we even had security teams as a dedicated role, sysadmins mostly handled security, and we would evaluate each CVE and determined if it even was applicable.
Then companies started hiring paper pushers into security roles and discretion no longer mattered, it just became a game of "Check the box" with no regard for what is actually running in prod, or whether you're actually vulnerable.
Same shit with auditors. I deal with PCI and it's a fight to explain why the "compensating controls" work to a non technical auditor. If it doesn't check the box exactly, good luck.
Setting aside the merits of DEI, this anecdote isn't indicative of it. I recall a client getting HP to do a security audit of a site I was working on, and it absolutely read like a committee put together a checklist of every possible thing they could think of. They flagged that user sessions weren't pinned to IP addresses, despite this being right around the time that cell phones became popular and their suggested remediation would have caused users who were riding on a bus between cell towers to get logged out while they were using the site.
There were plenty of even less useful flags, but that one stood out to me for some reason.
Author is from Latvia (and so am I). You do actually get carded for energy drinks if you look under 30.
However, more relevant to the post, is that when you're ordering groceries online, you need to verify your age at checkout if you're buying stuff like alcohol (or energy drinks). It's trivial, and for a lot of people it uses the same authentication service that they already use to access their bank.
I think almost all of Europe. Have you ever tried teaching a room of 30ish teenagers all high on quadrupled RDI of caffeine? It makes distributing software on macOS seem like a walk in the park
The UK also has a big issue with "corner shops" (tiny stores operated usually by one person) that are fronts for organised crime and will sell you a lot more than energy drinks without checking your ID. Cash payment usually preferred.
Also things are going to get hot at the next general election if you're following what just happened in this week's council elections.
I think those were aimed at different market segments. And that would be engineers, professionals and working academics that is not students.
Generally limitations in education on what was allowed led to more limited feature sets. Where as full feature set that could be upsold with qwerty keyboard was aimed for different users.
I bought a phone on eBay last month. The seller insured it with USPS. When the phone arrived with a cracked screen (the listing had photos of a not-cracked screen) I photographed the damage and submitted a return request with eBay. The seller then filed an insurance claim with USPS.
USPS sent me a letter, requiring me to present the damaged package (and its contents) to my local postmaster. I documented this to the seller via eBay, but complied with the government authority -- I didn't want the seller to lose his insurance claim because I didn't comply. The postmaster kept the package, saying it was a requirement.
Once the phone was out of my hands, the seller denied the return, keeping my money, while presumably keeping the money from the USPS insurance claim.
I've come to the conclusion that anything under about $500 isn't worth trying to sell online anymore. eBay has eroded as a marketplace for sellers.
For anything higher value, I have hobbyist forums I have 20 year memberships on where I can spend the time to due diligence individual buyers and transactions thoroughly. Even here I often don't get maximum dollars as I may have 3 offers and go with the person I am most comfortable transacting with.
And even on the higher end, it's easier to just do a trade in at a retailer instead of trying to extract maximum value doing business online.
On the lower end the problem is it's not worth the time to do the due diligence, and there are a tremendous number of time wasting tire kickers for lower value items. So I end up giving stuff away or just holding on to it, which is a shame.
> anything under about $500 isn't worth trying to sell online anymore
Anything under say $100 I'm fine selling on ebay because a) it's less likely to be scammed and b) even if it is, I don't care that much. Anything over that amount is only being sold in person on fb marketplace. Or, like you said, on a hobbyist forum.
I agree that ebay has completely eroded for sellers. It's basically a ship and be pleasantly surprised later situation.
I’ve gotten comfortable with selling things very cheap on Craigslist.
E.g. a $300 recliner I’d sell for $25 because no one will give you hassle about it, and at that price, you can pick from several buyers the one that is least likely to be a headache.
I was looking for a phone. Lots of sellers will list things as brand new which should imply new in box (unopened packaging). After you carefully read the listing, they actually mean open box which is far more variable.
Ebay does not care at all. It makes the search basically useless.