SHARE
Facebook X Pinterest WhatsApp

Chrome Pwnd

Mar 9, 2012

Want to uncover security flaws in your product before the bad guys do? Just put a big pile of money on the table.

Security researchers collected over $60,000 in prize money on Wednesday for reporting new zero-day flaws in Google’s Chrome web browser at the Pwn2Own and Pwnium security challenges held during the CanSecWest conference.

Google’s Chrome browser survived the gauntlet of hacker challenges at the Pwn2Own hacking challenge in 2011, but this year it was the first to fall — and it took less than 5 minutes to do it. The Pwn2Own Chrome exploit was popped by security research group VUPEN.

“Google Chrome is the first browser to fall at #pwn2own 2012, we pwned it using an exploit bypassing DEP/ASLR and the sandbox!” VUPEN wrote in a tweet yesterday afternoon.

DEP (Data Execution Prevention) is a security technology that is intended to help keep code that has been loaded into non-executable memory locations from being allowed to execute. ASLR (Address Space Layout Randmonization) is a similar kind of idea as a technology that attempts to make it more difficult for non-allocated memory to be used as a launch pad for attack. Both DEP and ASLR have been attacked and defeated at Pwn2Own as far back as 2009.

For its part, Google mocked the Pwn2Own VUPEN win as being just a Flash bug. Chrome is the only web browser that directly integrates Flash into the browser.


Read the full story at eSecurityPlanet:
Chrome Hacked at Pwn2Own and Pwnium Contests

Sean Michael Kerner is a senior editor at InternetNews.com, the news service of the IT Business Edge Network, the network for technology professionals. Follow him on Twitter @TechJournalist.

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.