Get a Pentest and security assessment of your IT network.

News

A EULOGY FOR PATCH-GAPPING CHROME

Authors: Istvn Kurucsai and Vignesh S Rao looked at patch gapping Chrome on two separate occasions. The conclusion was that exploiting 1day vulnerabilities well before the fixes were distributed through the stable channel is feasible and allows potential attackers to have 0day-like capabilities with only known vulnerabilities. This is compounded by the fact that regression tests are often included with patches, reducing exploit development time significantly. The vulnerability results from this oversight, as JSCreate accesses the prototype of the new JSCallReducer target, which can be intercepted by a Proxy.”]

Source: https://blog.exodusintel.com/2020/02/24/a-eulogy-for-patch-gapping-chrome/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin